
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50659 is a spoofing vulnerability in the .NET SMTP client implementation (System.Net.Mail) caused by improper encoding or escaping of output (CWE-116). It allows an authorized, low-privileged attacker to spoof messages during SMTP message routing over a network. The vulnerability was disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 flaws. Affected products include .NET 8.0 (< 8.0.29), .NET 9.0 (< 9.0.18), .NET 10.0 (< 10.0.10), .NET Framework 3.5/4.6.2/4.7/4.7.1/4.7.2/4.8/4.8.1, Visual Studio 2022 versions 17.12 (< 17.12.22) and 17.14 (< 17.14.36), and Visual Studio 2026 version 18.7 (< 18.7.4). It carries a CVSS v3.1 base score of 6.5 (Medium) (MSRC Advisory, GitHub Advisory).
The root cause is CWE-116 (Improper Encoding or Escaping of Output) in the System.Net.Mail SMTP client component of .NET. When constructing SMTP messages, the library fails to properly encode or escape certain output, allowing an attacker to inject content that alters the intended structure of SMTP messages during routing. Exploitation requires the attacker to have low-level network access and valid (low-privilege) credentials — no user interaction is needed. The vulnerability affects all platforms and architectures running the impacted .NET runtime packages (GitHub Advisory, MSRC Advisory).
Successful exploitation allows an authorized attacker to spoof SMTP messages during routing, potentially impersonating legitimate senders or forging email communications originating from affected .NET applications. The integrity impact is rated High, while there is no confidentiality or availability impact. This could enable phishing campaigns, business email compromise scenarios, or bypass of email-based security controls in applications relying on System.Net.Mail for message delivery (GitHub Advisory, MSRC Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (MSRC Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.415% (0.55% per GitHub Advisory), placing it in the lower-to-mid range of exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
Microsoft has released patched versions addressing this vulnerability. Organizations should update to the following minimum versions:
Self-contained applications targeting affected versions must be recompiled and redeployed after updating the SDK. Visual Studio users will be prompted to update via the IDE. Run dotnet --info to verify installed versions (GitHub Advisory, MSRC Advisory).
The vulnerability was covered as part of Microsoft's July 2026 Patch Tuesday, which was notable for fixing a record 570 vulnerabilities including three zero-days. BleepingComputer reported on the broader Patch Tuesday release, and Microsoft published servicing update details via the .NET developer blog. The vulnerability itself received moderate attention given its medium severity and lack of active exploitation (BleepingComputer, .NET Dev Blog).
Fix availability across major Linux distributions and their releases.
RHEL 8
:appstream:dotnet10.0-0:10.0.110-1.el8_10.src
RHEL 9
:appstream:dotnet8.0-0:8.0.130-1.el9_4.src
RHEL 10
dotnet8.0-0:8.0.130-1.el10_0.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."