CVE-2026-58649HighCVSS 6.5
.NET Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
🎯 Affected products14
- .NET 10.0 installed on Linux
- .NET 10.0 installed on Mac OS
- .NET 10.0 installed on Windows
- .NET 11.0 installed on Linux
- .NET 11.0 installed on Mac OS
- .NET 11.0 installed on Windows
- .NET 8.0 installed on Linux
- .NET 8.0 installed on Mac OS
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- Microsoft Visual Studio 2022 version 17.14
- Microsoft Visual Studio 2026 version 18.9
✅ Remediation
KBRelease Notes (Security Update) — fixed build 17.14.40 Security Update — fixed build 11.0 RC1 KB5126104 (Security Update) — fixed build 8.0.130, 8.0.424 KB5126105 (Security Update) — fixed build 9.0.120, 9.0.317 KBRelease Notes (Security Update) — fixed build 18.9.3 KB5126106 (Security Update) — fixed build 10.0.111, 10.0.400
🔗 References (12)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58649
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=Visual Studio 2022 17.14.40
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
- patchhttps://dotnet.microsoft.com/download/dotnet/11.0
- patchhttps://dotnet.microsoft.com/download/dotnet/8.0
- referencehttps://support.microsoft.com/help/5126104
- patchhttps://dotnet.microsoft.com/download/dotnet/9.0
- referencehttps://support.microsoft.com/help/5126105
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=Visual Studio 2026 18.9.3
- referencehttps://learn.microsoft.com/en-us/visualstudio/releases/2026/release-notes
- patchhttps://dotnet.microsoft.com/download/dotnet/10.0
- referencehttps://support.microsoft.com/help/5126106