Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-50659
vulnerability analysis and mitigation

Overview

CVE-2026-50659 is a spoofing vulnerability in the .NET SMTP client implementation (System.Net.Mail) caused by improper encoding or escaping of output (CWE-116). It allows an authorized, low-privileged attacker to spoof messages during SMTP message routing over a network. The vulnerability was disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 flaws. Affected products include .NET 8.0 (< 8.0.29), .NET 9.0 (< 9.0.18), .NET 10.0 (< 10.0.10), .NET Framework 3.5/4.6.2/4.7/4.7.1/4.7.2/4.8/4.8.1, Visual Studio 2022 versions 17.12 (< 17.12.22) and 17.14 (< 17.14.36), and Visual Studio 2026 version 18.7 (< 18.7.4). It carries a CVSS v3.1 base score of 6.5 (Medium) (MSRC Advisory, GitHub Advisory).

Technical details

The root cause is CWE-116 (Improper Encoding or Escaping of Output) in the System.Net.Mail SMTP client component of .NET. When constructing SMTP messages, the library fails to properly encode or escape certain output, allowing an attacker to inject content that alters the intended structure of SMTP messages during routing. Exploitation requires the attacker to have low-level network access and valid (low-privilege) credentials — no user interaction is needed. The vulnerability affects all platforms and architectures running the impacted .NET runtime packages (GitHub Advisory, MSRC Advisory).

Impact

Successful exploitation allows an authorized attacker to spoof SMTP messages during routing, potentially impersonating legitimate senders or forging email communications originating from affected .NET applications. The integrity impact is rated High, while there is no confidentiality or availability impact. This could enable phishing campaigns, business email compromise scenarios, or bypass of email-based security controls in applications relying on System.Net.Mail for message delivery (GitHub Advisory, MSRC Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (MSRC Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.415% (0.55% per GitHub Advisory), placing it in the lower-to-mid range of exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).

Mitigation and workarounds

Microsoft has released patched versions addressing this vulnerability. Organizations should update to the following minimum versions:

  • .NET 8.0: 8.0.29+
  • .NET 9.0: 9.0.18+
  • .NET 10.0: 10.0.10+
  • Visual Studio 2022 v17.12: 17.12.22+
  • Visual Studio 2022 v17.14: 17.14.36+
  • Visual Studio 2026 v18.7: 18.7.4+
  • .NET Framework: Apply corresponding July 2026 cumulative updates (e.g., 4.8.4803.0, 4.8.9339.0/4.8.9340.0, 4.7.4143.0)

Self-contained applications targeting affected versions must be recompiled and redeployed after updating the SDK. Visual Studio users will be prompted to update via the IDE. Run dotnet --info to verify installed versions (GitHub Advisory, MSRC Advisory).

Community reactions

The vulnerability was covered as part of Microsoft's July 2026 Patch Tuesday, which was notable for fixing a record 570 vulnerabilities including three zero-days. BleepingComputer reported on the broader Patch Tuesday release, and Microsoft published servicing update details via the .NET developer blog. The vulnerability itself received moderate attention given its medium severity and lack of active exploitation (BleepingComputer, .NET Dev Blog).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Fixed

devel

dotnet10

Not Affected

jammy

dotnet6

Deferred

noble

dotnet8: 8.0.129-8.0.29-0ubuntu1~24.04.1

Fixed

resolute

dotnet10: 10.0.110-10.0.10-0ubuntu1~26.04.1

Fixed

RHEL / CentOS

Fixed

RHEL 8

:appstream:dotnet10.0-0:10.0.110-1.el8_10.src

Fixed

RHEL 9

:appstream:dotnet8.0-0:8.0.130-1.el9_4.src

Fixed

RHEL 10

dotnet8.0-0:8.0.130-1.el10_0.src

Fixed

Alpine

Fixed

edge

dotnet10-runtime: 10.0.10-r0, 8.0.29-r0, 9.0.18-r0

Fixed

v3.22

dotnet8-runtime: 8.0.29-r0, 9.0.18-r0

Fixed

v3.23

dotnet10-runtime: 10.0.10-r0, 8.0.29-r0, 9.0.18-r0

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management