CVE-2026-26127 is an out-of-bounds read vulnerability in .NET, impacting products from Apple, Linux, and Microsoft. Rated as high severity (CVSS 7.5), it allows an unauthenticated attacker to remotely cause a denial of service with low attack complexity. There is no evidence of active exploitation or public exploit code available, but the vulnerability has received moderate community and media attention, including mentions in March 2026 Patch Tuesday reports. Organizations should prioritize patching to mitigate the risk of denial of service.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.0.4CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.14CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.14CPE matchmatch criteria | cpe:2.3:a:microsoft:bcl.memory:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.4CPE matchmatch criteria | cpe:2.3:a:microsoft:bcl.memory:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
.NET Denial of Service Vulnerability
Mar 11, 2026.NET Denial of Service Vulnerability
Mar 10, 2026Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability
Mar 10, 2026Microsoft Security Advisory .NET Denial of Service Vulnerability
Mar 10, 2026.NET Denial of Service Vulnerability
Mar 10, 2026Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability
Mar 10, 2026Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability
Mar 10, 2026