Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-26701

47
FAUCET Score

CVE-2021-26701 is a critical Remote Code Execution vulnerability affecting various Microsoft .NET, .NET Core, PowerShell Core, and Visual Studio 2019 products, as well as Fedora Project derivatives. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community discussion and media coverage, including warnings from Microsoft. Despite its high risk score and media attention, it is not listed on CISA's Known Exploited Vulnerabilities catalog and is currently inactive on the Hot List.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0, < 5.0.4CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 2.1, < 2.1.28CPE matchmatch criteria
cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:*
>= 3.1, < 3.1.15CPE matchmatch criteria
cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:a:microsoft:powershell_core:7.0:*:*:*:*:*:*:*
7.1CPE matchmatch criteria
cpe:2.3:a:microsoft:powershell_core:7.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
30.31%
Probability of exploitation in next 30 days
EPSS Percentile
98.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.3031 is in the 95th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

microsoftpatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: .NET Core 2.1
View patch
microsoftpatch availablevia msrc
Product: .NET Core 3.1
View patch
microsoftpatch availablevia msrc
Product: .NET 5.0
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
View patch
microsoftpatch availablevia msrc
Product: Visual Studio 2019 for Mac
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.8 (includes 16.0 - 16.7)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
View patch
microsoftpatch availablevia msrc
Product: PowerShell Core 7.1
View patch
microsoftpatch availablevia msrc
Product: PowerShell Core 7.0
View patch
nugetpatch availablevia ghsa
Product: System.Text.Encodings.WebFixed in: 4.7.2
nugetpatch availablevia ghsa
Product: System.Text.Encodings.WebFixed in: 5.0.1
nugetpatch availablevia ghsa
Product: System.Text.Encodings.WebFixed in: 4.5.1
redhatpatch availablevia redhat_api
Product: .NET Core on Red Hat Enterprise LinuxFixed in: rh-dotnet21-0:2.1-25.el7_9
View patch
redhatpatch availablevia redhat_api
Product: .NET Core on Red Hat Enterprise LinuxFixed in: rh-dotnet21-dotnet-0:2.1.522-1.el7_9
View patch
redhatpatch availablevia redhat_api
Product: .NET Core on Red Hat Enterprise LinuxFixed in: rh-dotnet31-dotnet-0:3.1.113-1.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dotnet-0:2.1.522-1.el8_3
View patch
redhatpatch availablevia redhat_api
Product: .NET Core on Red Hat Enterprise LinuxFixed in: rh-dotnet50-dotnet-0:5.0.104-1.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dotnet5.0-0:5.0.104-1.el8_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dotnet3.1-0:3.1.113-1.el8_3
View patch
chainsafevendor investigatingvia llm_extracted
gogsvendor investigatingvia llm_extracted
openpgpjsvendor investigatingvia llm_extracted
opensslvendor investigatingvia llm_extracted

Vendor Advisories (7)

openpgpjsllm-openpgpjs-6c87a05d15e6bdacCRITICAL

.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS

May 24, 2023
opensslllm-openssl-264845e84de177a0CRITICAL

.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS

May 24, 2023
gogsllm-gogs-d7d5575f002d975bCRITICAL

.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS

May 24, 2023
chainsafellm-chainsafe-8eb88ea97da43952CRITICAL

.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS

May 24, 2023
nugetGHSA-ghhp-997w-qr28critical

.NET Core Remote Code Execution Vulnerability

Apr 21, 2021
redhatCVE-2021-26701Important

dotnet: System.Text.Encodings.Web Remote Code Execution

Feb 25, 2021
microsoft2021-Feb/CVE-2021-26701Critical

.NET Core Remote Code Execution Vulnerability

Feb 9, 2021

References

lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/S2AZOUKMCHT2WBHR7MYDTYXWOBHZW5P5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TW3ZSJTTMZAFKGW7NJWTVVFZUYYU2SJZ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UBOSSX7U6BSHV5RI74FCOW4ITJ5RRJR5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WA5WQJVHUL5C4XMJTLY3C67R4WP35EF4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XPUKFHIGP5YNJRRFWKDJ2XRS4WTFJNNK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YLFATXASXW4OV2ZBSRP4G55HJH73QPBP
portal.msrc.microsoft.com / en-US/security-guidance/advisory/CVE-2021-26701
PatchVendor Advisory