CVE-2026-26171 is an uncontrolled resource consumption vulnerability affecting .NET that allows unauthorized attackers to cause denial of service over a network without requiring authentication or user interaction. The vulnerability has a CVSS score of 7.5 (HIGH) with a network-based attack vector, low complexity, and no privilege requirements, resulting in high availability impact to affected systems. Current exploitation indicators suggest this vulnerability is not actively being exploited in the wild, as it does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains on the inactive hot list. The EPSS score of 0.0056 indicates relatively low probability of exploitation compared to other published vulnerabilities, suggesting limited community attention and exploit availability at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.0.6CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.26CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.15CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 7.5, < 7.5.6CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:* | ||
>= 7.6, < 7.6.1CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.