Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32178

31
FAUCET Score

CVE-2026-32178 is a spoofing vulnerability in .NET resulting from improper neutralization of special elements, which could allow unauthenticated attackers to conduct network-based spoofing attacks against affected systems. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, reflecting its network-exploitable nature with low attack complexity and no required user interaction, though it impacts confidentiality rather than availability or integrity. The vulnerability demonstrates minimal exploitation activity based on its very low EPSS score of 0.0004, indicating it ranks below 0.12% of all known CVEs in exploitation likelihood, and it has not been added to CISA's Known Exploited Vulnerabilities catalog. Community attention remains limited with a FAUCET Risk Score of 48.0 out of 100, and there is currently no evidence of active exploitation or widespread availability of functional exploit code. Organizations should prioritize patching based on their .NET deployment footprint and exposure to untrusted network sources, though the lack of active exploitation suggests moderate urgency relative to other vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.0.0, < 10.0.6CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 8.0.0, < 8.0.26CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.15CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 17.12.0, < 17.12.19CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
>= 17.14.0, < 17.14.30CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.28%
Probability of exploitation in next 30 days
EPSS Percentile
81.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0228 is in the 67th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (49)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.12Fixed in: 17.12.19
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.14Fixed in: 17.14.30
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on WindowsFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on Mac OSFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on LinuxFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0Fixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on LinuxFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on WindowsFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on Mac OSFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on LinuxFixed in: 9.0.15
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on WindowsFixed in: 9.0.15
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on Mac OSFixed in: 9.0.15
View patch
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-armFixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-arm64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-armFixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-arm64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-x64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-x64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.osx-arm64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.osx-x64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-armFixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-arm64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-x64Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-x86Fixed in: 9.0.15
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-armFixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-arm64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-armFixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-arm64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-x64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-x64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-armFixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.osx-x64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-armFixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-arm64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-x64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-x86Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.osx-arm64Fixed in: 8.0.26
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-armFixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-arm64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-x64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-musl-arm64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.linux-x64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.osx-arm64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.osx-x64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-armFixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-arm64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-x64Fixed in: 10.0.6
nugetpatch availablevia ghsa
Product: Microsoft.NetCore.App.Runtime.win-x86Fixed in: 10.0.6
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

nugetGHSA-vmwf-m9c5-3jvclow

Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability

Apr 14, 2026
microsoft2026-Apr/CVE-2026-32178Important

.NET Spoofing Vulnerability

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:13280
access.redhat.com / errata/RHSA-2026:13281
access.redhat.com / errata/RHSA-2026:13282
access.redhat.com / errata/RHSA-2026:13283
access.redhat.com / errata/RHSA-2026:13693
access.redhat.com / errata/RHSA-2026:8467
access.redhat.com / errata/RHSA-2026:8468
access.redhat.com / errata/RHSA-2026:8469
access.redhat.com / errata/RHSA-2026:8470
access.redhat.com / errata/RHSA-2026:8471
access.redhat.com / errata/RHSA-2026:8472
access.redhat.com / errata/RHSA-2026:8473
access.redhat.com / errata/RHSA-2026:8474
access.redhat.com / errata/RHSA-2026:8475
access.redhat.com / errata/RHSA-2026:9077
access.redhat.com / errata/RHSA-2026:9080
access.redhat.com / errata/RHSA-2026:9205
access.redhat.com / security/cve/CVE-2026-32178
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-32178.json
msrc.microsoft.com / update-guide/vulnerability/CVE-2026-32178
Vendor Advisory