HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-50528

CVSS 8.2v3.1pub. 2026-07-14upd. 2026-07-22

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  • Apple macOS

    OS
    Apple
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft .net

    APP
    Microsoft
    9.0.0 – 9.0.18 (excl.)8.0.0 – 8.0.29 (excl.)10.0.0 – 10.0.6 (excl.)
  • Microsoft Visual Studio 2022

    APP
    Microsoft
    17.14.0 – 17.14.36 (excl.)17.12.0 – 17.12.22 (excl.)
  • Microsoft Visual Studio 2026

    APP
    Microsoft
    18.7.0 – 18.7.4 (excl.)
  • Microsoft Windows

    OS
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP