CVE-2026-50649
.NET SDK vulnerability analysis and mitigation

Overview

CVE-2026-50649 is a deserialization of untrusted data vulnerability in Microsoft .NET and .NET Framework that allows an unauthorized local attacker to execute arbitrary code. It was disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. Affected products include .NET 8.0 (before 8.0.29), .NET 9.0 (before 9.0.18), .NET Framework versions 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1, as well as Visual Studio 2026 (before 18.7.4) and Visual Studio 2022 versions 17.12 and 17.14. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, BleepingComputer).

Technical details

The root cause is improper deserialization of untrusted data (CWE-502), mapped to CAPEC-586 (Object Injection), within the .NET runtime and .NET Framework. An attacker can craft a malicious serialized object payload and deliver it to a vulnerable application that deserializes user-controlled input without adequate validation, triggering arbitrary code execution. Exploitation requires local access and user interaction — for example, convincing a user to open a maliciously crafted file or data stream processed by a vulnerable .NET application. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation grants an unauthenticated local attacker the ability to execute arbitrary code with the privileges of the vulnerable .NET application process, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could access sensitive data, modify application state, cause denial of service, or use the compromised process as a pivot point for further lateral movement within the environment. The scope is limited to the local system (unchanged scope), but the breadth of affected .NET versions means a wide range of Windows and Linux applications built on these runtimes are potentially at risk (Microsoft MSRC, Feedly).

Exploitation steps

  1. Reconnaissance: Identify target systems running vulnerable versions of .NET (8.0.0–8.0.28, 9.0.0–9.0.17), .NET Framework (3.5, 4.6.2–4.8.1), or Visual Studio 2026 (before 18.7.4) that process externally supplied serialized data.
  2. Craft malicious payload: Create a specially crafted serialized object (e.g., using tools like ysoserial.net) that exploits unsafe deserialization gadget chains present in the vulnerable .NET runtime.
  3. Deliver payload: Deliver the malicious serialized data to the target — for example, via a crafted file (document, configuration, or data file) that a local user or application will open and deserialize.
  4. Trigger deserialization: Induce the target application to deserialize the malicious object, either through social engineering (convincing a user to open the file) or by placing the payload in a location the application automatically processes.
  5. Achieve code execution: The deserialization gadget chain executes arbitrary commands with the privileges of the .NET application process, enabling actions such as spawning a shell, exfiltrating data, or establishing persistence (Microsoft MSRC).

Indicators of compromise

  • Process: Unexpected child processes spawned by .NET application processes (e.g., cmd.exe, powershell.exe, bash) with unusual parent-child relationships.
  • File System: Presence of unexpected or newly created executable files, scripts, or web shells in directories writable by the .NET application service account; unusual modification timestamps on .NET runtime assemblies.
  • Logs: Application event logs or .NET runtime logs showing deserialization exceptions or type resolution errors for unexpected types; Windows Event ID 4688 showing unusual process creation from .NET host processes.
  • Network: Unexpected outbound network connections from .NET application processes to external or internal IP addresses not associated with normal application behavior.

Mitigation and workarounds

Microsoft released patches on July 14, 2026 (Patch Tuesday). Users should update to the following fixed versions: .NET 8.0 → 8.0.29 or later; .NET 9.0 → 9.0.18 or later; .NET Framework 4.8 → 4.8.4803.0 or later; .NET Framework 4.8.1 → 4.8.9340.0 or later; .NET Framework 4.6.2/4.7/4.7.1/4.7.2 → 4.7.4143.0 or later; Visual Studio 2026 → 18.7.4 or later; Visual Studio 2022 17.14 → 17.14.36 or later; Visual Studio 2022 17.12 → 17.12.22 or later. As a workaround, limit local access to systems running vulnerable .NET versions and implement application-level controls to prevent deserialization of untrusted or externally supplied data. Red Hat has also issued advisories (RHSA-2026:42145, RHSA-2026:41899) for affected Linux distributions (Microsoft MSRC, .NET Dev Blog, Red Hat).

Community reactions

The July 2026 Patch Tuesday was widely covered due to the record-breaking 570 vulnerabilities addressed, with CVE-2026-50649 noted as part of the .NET servicing updates. BleepingComputer highlighted the scale of the release, and the Microsoft .NET team published a dedicated servicing update blog post. Rapid7 included the vulnerability in their Patch Tuesday analysis. Community discussion on Windows forums focused on the update process for .NET 8.0.29 and the breadth of affected framework versions (BleepingComputer, .NET Dev Blog, Rapid7).

Additional resources


SourceThis report was generated using AI

Related .NET SDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-50650HIGH7.8
  • C# logoC#
  • dotnet9.0-debuginfo
NoYesJul 14, 2026
CVE-2026-50649HIGH7.8
  • .NET SDK logo.NET SDK
  • aspnetcore-runtime-8.0
NoYesJul 14, 2026
CVE-2026-50651HIGH7.5
  • C# logoC#
  • aspnetcore-runtime-8.0
NoYesJul 14, 2026
CVE-2026-50648HIGH7.5
  • C# logoC#
  • dotnet10.0-debugsource
NoYesJul 14, 2026
CVE-2026-50659MEDIUM6.5
  • C# logoC#
  • dotnet9.0-debugsource
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management