Deserialization Vulnerability in .NET Framework by Microsoft
CVE-2026-50649
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2026-50649?
A vulnerability in the .NET Framework allows an unauthorized attacker to remotely execute arbitrary code through deserialization of untrusted data. This flaw can potentially compromise system security if exploited, making it crucial for users to apply necessary patches and updates to mitigate the risk.
Affected Version(s)
.NET 8.0 8.0.0 < 8.0.29
.NET 9.0 9.0.0 < 9.0.18
Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1607 for 32-bit Systems 4.7.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0