CyberICT

CVE-2026-50526

Microsoft · Published July 14, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

.NET Tampering Vulnerability. Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

Affected Products

  • Microsoft Visual Studio 2022 version 17.12
  • .NET 9.0 installed on Mac OS
  • .NET 8.0 installed on Mac OS
  • .NET 9.0 installed on Linux

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C