
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26127 is a Denial of Service vulnerability in Microsoft .NET and the Microsoft.Bcl.Memory NuGet package caused by an out-of-bounds read when decoding malformed Base64Url input. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. Affected versions include .NET 9.0.0–9.0.13, .NET 10.0.0–10.0.3, and Microsoft.Bcl.Memory 9.0.0–9.0.13 and 10.0.0–10.0.3. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, GitHub Advisory).
The root cause is an out-of-bounds read (CWE-125) combined with improper validation of an array index (CWE-129) in the Base64Url decoding logic within .NET's runtime and the Microsoft.Bcl.Memory library. An unauthenticated remote attacker can send a specially crafted, malformed Base64Url-encoded input to a vulnerable .NET application, triggering the out-of-bounds memory read and causing the application to crash. No authentication, user interaction, or elevated privileges are required for exploitation, as the attack vector is entirely network-based with low complexity. No public proof-of-concept exploit code has been identified (GitHub Advisory, Microsoft MSRC).
Successful exploitation results in a denial of service, crashing affected .NET applications and services and causing a complete loss of availability for the targeted component. There is no impact on confidentiality or data integrity, as the vulnerability only enables an availability disruption. Any organization running vulnerable .NET 9.0 or 10.0 runtimes, or applications referencing the affected Microsoft.Bcl.Memory NuGet package in production, is at risk of service outages (GitHub Advisory, Microsoft MSRC).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.041% (0.00041), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported in connection with this CVE.
Microsoft released patches on March 10, 2026. Organizations should update .NET to version 9.0.14 or later (for .NET 9) or 10.0.4 or later (for .NET 10). Applications referencing the Microsoft.Bcl.Memory NuGet package should update to version 9.0.14 or 10.0.4 respectively, using NuGet Package Manager, the Package Manager Console (Update-Package -Id Microsoft.Bcl.Memory), or the .NET CLI (dotnet package update Microsoft.Bcl.Memory), followed by recompilation and redeployment. As an additional defense-in-depth measure, implement network segmentation to limit exposure of .NET services to untrusted networks, and monitor application logs for unexpected crashes or service restarts (GitHub Advisory, .NET Dev Blog).
The vulnerability received broad coverage as part of the March 2026 Patch Tuesday cycle, which addressed 83–84 total vulnerabilities. Security vendors including Tenable, Qualys, Rapid7, and Sophos highlighted CVE-2026-26127 in their Patch Tuesday roundups, noting it as one of two publicly disclosed zero-days in the release (Tenable Blog, Qualys Blog). Duende Software published a dedicated blog post noting that their products were affected by the Microsoft.Bcl.Memory dependency and released patch releases addressing the issue (Duende Software). Red Hat and Ubuntu also issued security advisories for their .NET packages in response to this CVE.
Fix availability across major Linux distributions and their releases.
RHEL 8
:appstream:dotnet10.0-0:10.0.104-1.el8_10.src
RHEL 9
:appstream:dotnet9.0-0:9.0.115-1.el9_6.src
RHEL 10
dotnet9.0-0:9.0.115-1.el10_0.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."