Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32203

29
FAUCET Score

CVE-2026-32203 is a stack-based buffer overflow vulnerability affecting .NET and Visual Studio that allows unauthenticated remote attackers to cause denial of service. The vulnerability can be triggered over a network without requiring user interaction or elevated privileges, making it broadly accessible to potential threat actors. This flaw presents a moderately elevated risk profile with a CVSS score of 7.5 (HIGH severity), though it does not enable data confidentiality or integrity compromise. The vulnerability does not currently appear on the Known Exploited Vulnerabilities (KEV) catalog and is not listed as actively exploited in the wild, indicating limited real-world attack activity at present. Community attention remains minimal, as evidenced by the low EPSS score of 0.00118, suggesting this vulnerability is not yet a significant exploitation vector compared to other known security flaws.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.0.0, < 10.0.6CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 8.0.0, < 8.0.26CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.15CPE matchmatch criteria
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
>= 17.12.0, < 17.12.19CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
>= 17.14.0, < 17.14.30CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.55%
Probability of exploitation in next 30 days
EPSS Percentile
72.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0155 is in the 54th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2026 version 18.4Fixed in: 18.4.4
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.12Fixed in: 17.12.19
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.14Fixed in: 17.14.30
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on WindowsFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on Mac OSFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 10.0 installed on LinuxFixed in: 10.0.6
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on WindowsFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on LinuxFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 8.0 installed on Mac OSFixed in: 8.0.26
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on LinuxFixed in: 9.0.15
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on Mac OSFixed in: 9.0.15
View patch
microsoftpatch availablevia msrc
Product: .NET 9.0 installed on WindowsFixed in: 9.0.15
View patch
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-32203Important

.NET and Visual Studio Denial of Service Vulnerability

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:13280
access.redhat.com / errata/RHSA-2026:13281
access.redhat.com / errata/RHSA-2026:13282
access.redhat.com / errata/RHSA-2026:13283
access.redhat.com / errata/RHSA-2026:13693
access.redhat.com / errata/RHSA-2026:8467
access.redhat.com / errata/RHSA-2026:8468
access.redhat.com / errata/RHSA-2026:8469
access.redhat.com / errata/RHSA-2026:8470
access.redhat.com / errata/RHSA-2026:8471
access.redhat.com / errata/RHSA-2026:8472
access.redhat.com / errata/RHSA-2026:8473
access.redhat.com / errata/RHSA-2026:8474
access.redhat.com / errata/RHSA-2026:8475
access.redhat.com / errata/RHSA-2026:9077
access.redhat.com / errata/RHSA-2026:9080
access.redhat.com / errata/RHSA-2026:9205
access.redhat.com / security/cve/CVE-2026-32203
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-32203.json
msrc.microsoft.com / update-guide/vulnerability/CVE-2026-32203
Vendor Advisory