
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50646 is a protection mechanism failure vulnerability in Microsoft .NET Framework and .NET that allows an unauthenticated local attacker to execute arbitrary code when a user interacts with a malicious file or input. It was disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. Affected products include .NET Framework 3.5, 4.6.2/4.7/4.7.1/4.7.2, 4.8, and 4.8.1; .NET 8.0 (before 8.0.29) and .NET 9.0 (before 9.0.18); and Microsoft Visual Studio 2022 (versions 17.12 and 17.14) and Visual Studio 2026 (version 18.7). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Red Hat Bugzilla).
The vulnerability is rooted in a protection mechanism failure (CWE-693) within .NET Framework's deserialization handling, also classified under CWE-502 (Deserialization of Untrusted Data) and CWE-807 (Reliance on Untrusted Inputs in a Security Decision). The attack vector is local, requiring no privileges but necessitating user interaction — consistent with a scenario where a victim opens or processes a maliciously crafted file or object. The failure allows the attacker to bypass security controls that should prevent unsafe deserialization or code execution, ultimately enabling arbitrary code to run in the context of the affected process. No public proof-of-concept code has been confirmed at the time of disclosure (Microsoft MSRC, Red Hat Bugzilla).
Successful exploitation allows an unauthenticated local attacker to execute arbitrary code with the privileges of the affected process, resulting in high confidentiality, integrity, and availability impact. An attacker could read, modify, or delete sensitive files, crash the affected system, and potentially escalate privileges or pivot to other resources accessible by the compromised process. The scope is limited to the affected system (unchanged scope), but the breadth of affected products — spanning multiple .NET Framework versions and Visual Studio installations — means a wide range of Windows environments could be at risk (Microsoft MSRC, Feedly).
cmd.exe, powershell.exe, wscript.exe) without user initiation; unusual process trees originating from Visual Studio or .NET runtime processes.Microsoft released patches on July 14, 2026 (Patch Tuesday). Users should update to the following fixed versions: .NET 8.0.29, .NET 9.0.18; .NET Framework 4.7.x to build 4.7.4143.0, .NET Framework 4.8 to 4.8.4803.0, .NET Framework 4.8.1 to 4.8.9339.0; Visual Studio 2022 17.12 to 17.12.22, Visual Studio 2022 17.14 to 17.14.36, and Visual Studio 2026 18.7 to 18.7.4. For systems where immediate patching is not feasible, restrict local access to untrusted users and monitor for suspicious local activity. Applying the security updates via Windows Update or the Microsoft Update Catalog is the recommended remediation (Microsoft MSRC, Microsoft .NET Blog).
The vulnerability was covered as part of Microsoft's record-breaking July 2026 Patch Tuesday, which fixed 570 flaws and three zero-days, drawing significant attention from the security community (BleepingComputer). Rapid7 included CVE-2026-50646 in their Patch Tuesday analysis, noting the breadth of affected .NET products (Rapid7). The SANS Internet Storm Center also noted the patch in their July 2026 diary entry (SANS ISC). Red Hat tracked the issue via Bugzilla for potential impact on .NET packages distributed on Linux (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."