.NET Information Disclosure VulnerabilityVendor advisorypatch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62900 CVE-2026-62900
MEDIUM
.NET Information Disclosure Vulnerability
Record summary
CVE-2026-62900 has a selected CVSS score of 5.9 (medium).
Description
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
Description source: NVD
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
.NET 10.0Browse Microsoft / .NET 10.0 | CVE List | 10.0.0 to < 10.0.11 | affected |
.NET 8.0Browse Microsoft / .NET 8.0 | CVE List | 8.0.0 to < 8.0.30 | affected |
.NET 9.0Browse Microsoft / .NET 9.0 | CVE List | 9.0.0 to < 9.0.19 | affected |
Microsoft Visual Studio 2022 version 17.14Browse Microsoft / Microsoft Visual Studio 2022 version 17.14 | CVE List | 17.14.0 to < 17.14.38 | affected |
Microsoft Visual Studio 2026 version 18.8Browse Microsoft / Microsoft Visual Studio 2026 version 18.8 | CVE List | 18.0 to < 18.8.3 | affected |