Record summary

CVE-2026-62900 has a selected CVSS score of 5.9 (medium).

Description

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

Description source: NVD

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus
CVE List10.0.0 to < 10.0.11affected
CVE List8.0.0 to < 8.0.30affected
CVE List9.0.0 to < 9.0.19affected

Microsoft Visual Studio 2022 version 17.14

Browse Microsoft / Microsoft Visual Studio 2022 version 17.14
CVE List17.14.0 to < 17.14.38affected

Microsoft Visual Studio 2026 version 18.8

Browse Microsoft / Microsoft Visual Studio 2026 version 18.8
CVE List18.0 to < 18.8.3affected

References

1