CVE-2026-50526
Microsoft · Published July 14, 2026
7.0
CVSS v3.1
HIGHPatch availableGet patch
Description
.NET Tampering Vulnerability. Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Affected Products
- Microsoft Visual Studio 2022 version 17.12
- .NET 9.0 installed on Mac OS
- .NET 8.0 installed on Mac OS
- .NET 9.0 installed on Linux
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C