CVE-2026-50649
Microsoft · Published July 14, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
.NET Remote Code Execution Vulnerability. Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Affected Products
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Windows
- Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based Systems
- Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C