Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-26171

29
FAUCET Score

CVE-2026-26171 is an uncontrolled resource consumption vulnerability affecting .NET that allows unauthorized attackers to cause denial of service over a network without requiring authentication or user interaction. The vulnerability has a CVSS score of 7.5 (HIGH) with a network-based attack vector, low complexity, and no privilege requirements, resulting in high availability impact to affected systems. Current exploitation indicators suggest this vulnerability is not actively being exploited in the wild, as it does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains on the inactive hot list. The EPSS score of 0.0056 indicates relatively low probability of exploitation compared to other published vulnerabilities, suggesting limited community attention and exploit availability at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.0.0, < 10.0.6CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 8.0.0, < 8.0.26CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.15CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 7.5, < 7.5.6CPE matchmatch criteria
cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:*
>= 7.6, < 7.6.1CPE matchmatch criteria
cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.75%
Probability of exploitation in next 30 days
EPSS Percentile
75.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0175 is in the 58th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

microsoftpatch availablevia msrc
Product: .NET 9.0 installed on WindowsFixed in: 9.0.15
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on Mac OSFixed in: 9.0.15
View patch
microsoftpatch availablevia msrc
Product: PowerShell 7.6Fixed in: 7.6.1
View patch
microsoftpatch availablevia msrc
Product: PowerShell 7.5Fixed in: 7.5.6
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on LinuxFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on Mac OSFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on WindowsFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on LinuxFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on Mac OSFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on LinuxFixed in: 9.0.15
View patch
nugetpatch availablevia ghsa
Product: System.Security.Cryptography.XmlFixed in: 10.0.6
nugetpatch availablevia ghsa
Product: System.Security.Cryptography.XmlFixed in: 9.0.15
nugetpatch availablevia ghsa
Product: System.Security.Cryptography.XmlFixed in: 8.0.3
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

nugetGHSA-w3x6-4m5h-cxqfhigh

Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability

Apr 14, 2026
microsoft2026-Apr/CVE-2026-26171Important

.NET Denial of Service Vulnerability

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:13280
access.redhat.com / errata/RHSA-2026:13281
access.redhat.com / errata/RHSA-2026:13282
access.redhat.com / errata/RHSA-2026:13283
access.redhat.com / errata/RHSA-2026:13693
access.redhat.com / errata/RHSA-2026:8467
access.redhat.com / errata/RHSA-2026:8468
access.redhat.com / errata/RHSA-2026:8469
access.redhat.com / errata/RHSA-2026:8470
access.redhat.com / errata/RHSA-2026:8471
access.redhat.com / errata/RHSA-2026:8472
access.redhat.com / errata/RHSA-2026:8473
access.redhat.com / errata/RHSA-2026:8474
access.redhat.com / errata/RHSA-2026:8475
access.redhat.com / errata/RHSA-2026:9077
access.redhat.com / errata/RHSA-2026:9080
access.redhat.com / errata/RHSA-2026:9205
access.redhat.com / security/cve/CVE-2026-26171
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-26171.json
msrc.microsoft.com / update-guide/vulnerability/CVE-2026-26171
Vendor Advisory