CVE-2026-26127
C# vulnerability analysis and mitigation

Overview

CVE-2026-26127 is a Denial of Service vulnerability in Microsoft .NET and the Microsoft.Bcl.Memory NuGet package caused by an out-of-bounds read when decoding malformed Base64Url input. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. Affected versions include .NET 9.0.0–9.0.13, .NET 10.0.0–10.0.3, and Microsoft.Bcl.Memory 9.0.0–9.0.13 and 10.0.0–10.0.3. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, GitHub Advisory).

Technical details

The root cause is an out-of-bounds read (CWE-125) combined with improper validation of an array index (CWE-129) in the Base64Url decoding logic within .NET's runtime and the Microsoft.Bcl.Memory library. An unauthenticated remote attacker can send a specially crafted, malformed Base64Url-encoded input to a vulnerable .NET application, triggering the out-of-bounds memory read and causing the application to crash. No authentication, user interaction, or elevated privileges are required for exploitation, as the attack vector is entirely network-based with low complexity. No public proof-of-concept exploit code has been identified (GitHub Advisory, Microsoft MSRC).

Impact

Successful exploitation results in a denial of service, crashing affected .NET applications and services and causing a complete loss of availability for the targeted component. There is no impact on confidentiality or data integrity, as the vulnerability only enables an availability disruption. Any organization running vulnerable .NET 9.0 or 10.0 runtimes, or applications referencing the affected Microsoft.Bcl.Memory NuGet package in production, is at risk of service outages (GitHub Advisory, Microsoft MSRC).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.041% (0.00041), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported in connection with this CVE.

Mitigation and workarounds

Microsoft released patches on March 10, 2026. Organizations should update .NET to version 9.0.14 or later (for .NET 9) or 10.0.4 or later (for .NET 10). Applications referencing the Microsoft.Bcl.Memory NuGet package should update to version 9.0.14 or 10.0.4 respectively, using NuGet Package Manager, the Package Manager Console (Update-Package -Id Microsoft.Bcl.Memory), or the .NET CLI (dotnet package update Microsoft.Bcl.Memory), followed by recompilation and redeployment. As an additional defense-in-depth measure, implement network segmentation to limit exposure of .NET services to untrusted networks, and monitor application logs for unexpected crashes or service restarts (GitHub Advisory, .NET Dev Blog).

Community reactions

The vulnerability received broad coverage as part of the March 2026 Patch Tuesday cycle, which addressed 83–84 total vulnerabilities. Security vendors including Tenable, Qualys, Rapid7, and Sophos highlighted CVE-2026-26127 in their Patch Tuesday roundups, noting it as one of two publicly disclosed zero-days in the release (Tenable Blog, Qualys Blog). Duende Software published a dedicated blog post noting that their products were affected by the Microsoft.Bcl.Memory dependency and released patch releases addressing the issue (Duende Software). Red Hat and Ubuntu also issued security advisories for their .NET packages in response to this CVE.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Fixed

RHEL 8

:appstream:dotnet10.0-0:10.0.104-1.el8_10.src

Fixed

RHEL 9

:appstream:dotnet9.0-0:9.0.115-1.el9_6.src

Fixed

RHEL 10

dotnet9.0-0:9.0.115-1.el10_0.src

Fixed

Alpine

Fixed

edge

dotnet10-runtime: 10.0.4-r0, 9.0.14-r0

Fixed

v3.21

dotnet9-runtime: 9.0.14-r0

Fixed

v3.22

dotnet9-runtime: 9.0.14-r0

Fixed

v3.23

dotnet10-runtime: 10.0.4-r0, 9.0.14-r0

Fixed

SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71328HIGH8.8
  • C# logoC#
  • Microsoft.DiaSymReader.Native
NoYesSep 08, 2026
CVE-2026-69522HIGH8.8
  • C# logoC#
  • dotnet10-runtime
NoYesSep 08, 2026
CVE-2026-69439HIGH8.8
  • C# logoC#
  • dotnet10-runtime
NoYesSep 08, 2026
CVE-2026-69304MEDIUM5.9
  • C# logoC#
  • dotnet9-runtime
NoYesSep 08, 2026
GHSA-cvhv-g4rq-3hmwLOW3.3
  • C# logoC#
  • Magick.NET-Q8-OpenMP-arm64
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management