CVE-2026-26127
.NET Denial of Service Vulnerability
Record summary
CVE-2026-26127 has a selected CVSS score of 7.5 (high); EIP currently links 1 curated repository PoC.
Description
# Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0 and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET and Microsoft.Bcl.Memory due to an out-of-bounds read when decoding malformed Base64Url input. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/384 ## CVSS Details - **Version:** 3.1 - **Score:** 7.5 - **Vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C` - **Severity:** High - **Weakness:** CWE-129 (Improper Validation of Array Index); CWE-125 (Out-of-bounds Read) ## Affected Platforms - **Platforms:** All - **Architectures:** All ## Affected Products ### <a name=".NET 9"></a>.NET 9 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.NetCore.App.Runtime.linux-arm](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-arm) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.linux-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-arm64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.linux-musl-arm](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-musl-arm) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.linux-musl-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-musl-arm64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.linux-musl-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-musl-x64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.linux-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-x64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.osx-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.osx-arm64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.osx-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.osx-x64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.win-arm](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-arm) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.win-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-arm64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.win-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-x64) | >= 9.0.0, <= 9.0.13 | 9.0.14 [Microsoft.NetCore.App.Runtime.win-x86](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-x86) | >= 9.0.0, <= 9.0.13 | 9.0.14 ### <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.NetCore.App.Runtime.linux-arm](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-arm) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.linux-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-arm64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.linux-musl-arm](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-musl-arm) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.linux-musl-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-musl-arm64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.linux-musl-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-musl-x64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.linux-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.linux-x64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.osx-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.osx-arm64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.osx-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.osx-x64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.win-arm](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-arm) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.win-arm64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-arm64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.win-x64](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-x64) | >= 10.0.0, <= 10.0.3 | 10.0.4 [Microsoft.NetCore.App.Runtime.win-x86](https://www.nuget.org/packages/Microsoft.NetCore.App.Runtime.win-x86) | >= 10.0.0, <= 10.0.3 | 10.0.4 ### <a name="Microsoft.Bcl.Memory 9.0.14"></a>Microsoft.Bcl.Memory 9.0.14 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.Bcl.Memory](https://www.nuget.org/packages/Microsoft.Bcl.Memory) | >= 9.0.0, <= 9.0.13 | 9.0.14 ### <a name="Microsoft.Bcl.Memory 10.0.4"></a>Microsoft.Bcl.Memory 10.0.4 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.Bcl.Memory](https://www.nuget.org/packages/Microsoft.Bcl.Memory) | >= 10.0.0, <= 10.0.3 | 10.0.4 ### <a name="how-fix"></a>How to fix the issue To update the Microsoft.Bcl.Memory NuGet package, apply one of the following methods: NuGet Package Manager UI in Visual Studio: - Open the project in Visual Studio. - Right-click on the project in Solution Explorer and select "Manage NuGet Packages..." or navigate to "Project > Manage NuGet Packages". - In the NuGet Package Manager window, select the "Updates" tab. This tab lists packages with available updates from the configured package sources. - Select the package(s) to update. A specific version can be chosen from the dropdown, or the latest available version can be selected. - Click the "Update" button. Using the NuGet Package Manager Console in Visual Studio: - Open the project in Visual Studio. - Navigate to "Tools > NuGet Package Manager > Package Manager Console". - To update a specific package to its latest version, run the following Update-Package command: ``` Update-Package -Id Microsoft.Bcl.Memory ``` Using the .NET CLI (Command Line Interface): - Open a terminal or command prompt in the project's directory. - To update a specific package to its latest version, run the following command: ``` dotnet package update Microsoft.Bcl.Memory ``` Once the NuGet package reference has been updated, the application must be recompiled and redeployed. Additionally, it is recommended to update the runtime and/or SDKs, but unless the application targets .NET 9 or higher, updating the runtime and/or SDK is not a required step to patch this vulnerability. ## Other Information ### Reporting Security Issues If a potential security issue has been found in a supported version of .NET, it should be reported to the Microsoft Security Response Center (MSRC) via the [MSRC Researcher Portal](https://msrc.microsoft.com/report/vulnerability/new). Further information can be found in the MSRC [Report an Issue FAQ](https://www.microsoft.com/msrc/faqs-report-an-issue). Security reports made through MSRC may qualify for the Microsoft .NET Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. ### Support Questions about this issue can be asked on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. Questions can be asked in the linked discussion issue. ### Disclaimer The information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. ### External Links [CVE-2026-26127](https://www.cve.org/CVERecord?id=CVE-2026-26127) ### Revisions V1.0 (March 10, 2026): Advisory published.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 13, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Curated repository PoCs
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 17| Product | Source | Version range | Status |
|---|---|---|---|
.NET 10.0Browse Microsoft / .NET 10.0 | CVE List | 10.0.0 to < 10.0.4 | affected |
.NET 9.0Browse Microsoft / .NET 9.0 | CVE List | 9.0.0 to < 9.0.14 | affected |
| VulnCheck | Version data not supplied | ||
Microsoft.Bcl.MemoryBrowse Microsoft / Microsoft.Bcl.Memory | CVE List | 10.0.0 to < 10.0.4 | affected |
| 9.0.0 to < 9.0.14 | affected | ||
Microsoft.Bcl.MemoryBrowse NuGet / Microsoft.Bcl.Memory | GitHub Advisory | 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected |
| 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected | ||
Microsoft.NetCore.App.Runtime.linux-armBrowse NuGet / Microsoft.NetCore.App.Runtime.linux-arm | GitHub Advisory | 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected |
| 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected | ||
Microsoft.NetCore.App.Runtime.linux-arm64Browse NuGet / Microsoft.NetCore.App.Runtime.linux-arm64 | GitHub Advisory | 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected |
| 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected | ||
Microsoft.NetCore.App.Runtime.linux-musl-armBrowse NuGet / Microsoft.NetCore.App.Runtime.linux-musl-arm | GitHub Advisory | 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected |
| 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected | ||
Microsoft.NetCore.App.Runtime.linux-musl-arm64Browse NuGet / Microsoft.NetCore.App.Runtime.linux-musl-arm64 | GitHub Advisory | 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected |
| 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected | ||
Microsoft.NetCore.App.Runtime.linux-musl-x64Browse NuGet / Microsoft.NetCore.App.Runtime.linux-musl-x64 | GitHub Advisory | 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected |
| 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected | ||
Microsoft.NetCore.App.Runtime.linux-x64Browse NuGet / Microsoft.NetCore.App.Runtime.linux-x64 | GitHub Advisory | 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected |
| 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected | ||
Microsoft.NetCore.App.Runtime.osx-arm64Browse NuGet / Microsoft.NetCore.App.Runtime.osx-arm64 | GitHub Advisory | 10.0.0 to < 10.0.4 · Fixed in 10.0.4 | affected |
| 9.0.0 to < 9.0.14 · Fixed in 9.0.14 | affected | ||
Proofs of concept
1Curated repository PoCs
GitHubCVE-2026-26118Curated repository PoCby SecureWithUmerStars: 34Scanner19 files
Analysis
Technical assessment
A Microsoft Sentinel analytics rule (KQL query) designed to detect a multi-stage attack chain involving Azure MCP Server managed identity abuse. It correlates MCP-related service principal sign-ins with subsequent privileged Azure operations (e.g., Key Vault access, role assignment modification) within a 30-minute window.
Backdoor review
No backdoor observed in reviewed code
The supplied evidence is a single JSON file defining a Microsoft Sentinel analytics rule for detecting post-exploitation activity related to CVE-2026-26118. The file contains only declarative KQL query logic and rule configuration; no executable code, obfuscation, or deceptive behavior is present.
Classification basis and observed behavior
Classification basis
The artifact is a Microsoft Sentinel scheduled analytics rule (JSON definition with an embedded KQL query) that detects post-exploitation activity. It does not contain any code to exploit a vulnerability; it only checks for indicators of compromise in log data.
j-dahl7-mcp-attack-detection-sentinel-a074553/analytics-rules/mcp-identity-post-exploitation.json:2-8Requirements
- Requires Microsoft Sentinel workspace with AADServicePrincipalSignInLogs and AzureActivity log data ingestion enabled.
j-dahl7-mcp-attack-detection-sentinel-a074553/analytics-rules/mcp-identity-post-exploitation.json:8
Observed behavior
- Defines a KQL query that joins AADServicePrincipalSignInLogs with AzureActivity logs to find successful privileged operations performed by an MCP-related service principal within 30 minutes of its sign-in.
j-dahl7-mcp-attack-detection-sentinel-a074553/analytics-rules/mcp-identity-post-exploitation.json:8 - The rule is configured to run every hour, look back over 1 day, and create an incident when any matching event is found.
j-dahl7-mcp-attack-detection-sentinel-a074553/analytics-rules/mcp-identity-post-exploitation.json:9-12
Behaviors behind the backdoor verdict
Observables
- Analytics Rule
- Payload withheldThe file is a Microsoft Sentinel scheduled analytics rule that correlates Azure MCP service principal sign-ins with subsequent privileged operations to detect potential abuse of managed identity tokens.
j-dahl7-mcp-attack-detection-sentinel-a074553/analytics-rules/mcp-identity-post-exploitation.json:1-58
What the analysis did not establish
- Only one text file (the analytics rule definition) was provided; the repository unit contains 18 other files (including 2 non-text media files) that were not included in the evidence packet.
- The evidence does not include any exploit code, proof-of-concept scripts, or technical writeups describing how to trigger the associated CVEs.
- Only one text file was provided; 2 non-text media files and 16 unclassified files were present in the artifact but not analyzed. Their content is unknown.
This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.