
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50649 is a deserialization of untrusted data vulnerability in Microsoft .NET and .NET Framework that allows an unauthorized local attacker to execute arbitrary code. It was disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. Affected products include .NET 8.0 (before 8.0.29), .NET 9.0 (before 9.0.18), .NET Framework versions 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1, as well as Visual Studio 2026 (before 18.7.4) and Visual Studio 2022 versions 17.12 and 17.14. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, BleepingComputer).
The root cause is improper deserialization of untrusted data (CWE-502), mapped to CAPEC-586 (Object Injection), within the .NET runtime and .NET Framework. An attacker can craft a malicious serialized object payload and deliver it to a vulnerable application that deserializes user-controlled input without adequate validation, triggering arbitrary code execution. Exploitation requires local access and user interaction — for example, convincing a user to open a maliciously crafted file or data stream processed by a vulnerable .NET application. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation grants an unauthenticated local attacker the ability to execute arbitrary code with the privileges of the vulnerable .NET application process, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could access sensitive data, modify application state, cause denial of service, or use the compromised process as a pivot point for further lateral movement within the environment. The scope is limited to the local system (unchanged scope), but the breadth of affected .NET versions means a wide range of Windows and Linux applications built on these runtimes are potentially at risk (Microsoft MSRC, Feedly).
cmd.exe, powershell.exe, bash) with unusual parent-child relationships.Microsoft released patches on July 14, 2026 (Patch Tuesday). Users should update to the following fixed versions: .NET 8.0 → 8.0.29 or later; .NET 9.0 → 9.0.18 or later; .NET Framework 4.8 → 4.8.4803.0 or later; .NET Framework 4.8.1 → 4.8.9340.0 or later; .NET Framework 4.6.2/4.7/4.7.1/4.7.2 → 4.7.4143.0 or later; Visual Studio 2026 → 18.7.4 or later; Visual Studio 2022 17.14 → 17.14.36 or later; Visual Studio 2022 17.12 → 17.12.22 or later. As a workaround, limit local access to systems running vulnerable .NET versions and implement application-level controls to prevent deserialization of untrusted or externally supplied data. Red Hat has also issued advisories (RHSA-2026:42145, RHSA-2026:41899) for affected Linux distributions (Microsoft MSRC, .NET Dev Blog, Red Hat).
The July 2026 Patch Tuesday was widely covered due to the record-breaking 570 vulnerabilities addressed, with CVE-2026-50649 noted as part of the .NET servicing updates. BleepingComputer highlighted the scale of the release, and the Microsoft .NET team published a dedicated servicing update blog post. Rapid7 included the vulnerability in their Patch Tuesday analysis. Community discussion on Windows forums focused on the update process for .NET 8.0.29 and the breadth of affected framework versions (BleepingComputer, .NET Dev Blog, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."