
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50659 is a spoofing vulnerability in Microsoft .NET caused by improper encoding or escaping of output (CWE-116). It affects .NET 8.0 (before 8.0.29), .NET 9.0 (before 9.0.18), .NET 10.0 (before 10.0.6), Microsoft Visual Studio 2022 versions 17.12 (before 17.12.22) and 17.14 (before 17.14.36), and Microsoft Visual Studio 2026 version 18.7 (before 18.7.4). The vulnerability was disclosed and patched on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 6.5 (Medium/High) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-116 (Improper Encoding or Escaping of Output), where .NET fails to properly encode or escape output in certain contexts, enabling content spoofing. An authenticated, low-privileged attacker can exploit this over the network without user interaction, making it a network-accessible, low-complexity attack. The attack vector is network-based with no user interaction required, but the attacker must have at least low-level authenticated access to the target system. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Microsoft MSRC, Feedly).
Successful exploitation allows an authorized, low-privileged attacker to perform network-based content spoofing, resulting in a high integrity impact with no confidentiality or availability impact. Attackers could manipulate or forge content presented to users or systems consuming .NET-based services, potentially enabling phishing, data manipulation, or trust abuse within affected applications. The scope is limited to the affected system (unchanged scope), but the integrity impact is rated high, indicating meaningful potential for data or content falsification (Microsoft MSRC, Feedly).
Microsoft released patches for all affected products on July 14, 2026, as part of Patch Tuesday. Organizations should update to the following fixed versions: .NET 8.0.29, .NET 9.0.18, .NET 10.0.6, Visual Studio 2022 17.12.22, Visual Studio 2022 17.14.36, and Visual Studio 2026 18.7.4. As a defense-in-depth measure, organizations should also review and audit .NET applications for proper output encoding practices. No specific configuration-based workaround has been published (Microsoft MSRC, .NET Dev Blog).
The vulnerability was covered as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities including three zero-days, drawing significant industry attention. BleepingComputer and Rapid7 both covered the broader Patch Tuesday release, noting the scale of the update cycle. The SANS Internet Storm Center also published a diary entry covering the July 2026 updates (BleepingComputer, Rapid7, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."