CVE-2026-62902
C# vulnerability analysis and mitigation

Overview

CVE-2026-62902 is an information disclosure vulnerability in Microsoft .NET caused by inclusion of functionality from an untrusted control sphere (CWE-829), effectively enabling Server-Side Request Forgery (SSRF) conditions. It was disclosed on August 11, 2026, as part of Microsoft's August 2026 Patch Tuesday release. Affected products include .NET 8.0 (versions 8.0.0–8.0.29), .NET 9.0 (versions 9.0.0–9.0.18), .NET 10.0 (versions 10.0.0–10.0.10), Microsoft Visual Studio 2022 version 17.14 (before 17.14.38), and Microsoft Visual Studio 2026 version 18.8 (before 18.8.3). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Microsoft MSRC, Feedly).

Technical details

The root cause is classified under CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), CWE-693 (Protection Mechanism Failure), and CWE-918 (Server-Side Request Forgery). The vulnerability allows .NET to load or reference functionality from an attacker-controlled or untrusted source, which can be leveraged to cause the application to make network requests that disclose sensitive information to an unauthorized party. Exploitation requires user interaction (e.g., a victim opening a malicious file or visiting a crafted page), but no authentication or elevated privileges are needed on the attacker's side. No public proof-of-concept code has been identified at this time (Microsoft MSRC, GitHub Advisory).

Impact

Successful exploitation results in high confidentiality impact — sensitive information can be disclosed over the network to an unauthenticated attacker. Integrity and availability are not affected. The SSRF-like nature of the flaw means an attacker could potentially cause the vulnerable .NET application to exfiltrate data to an external server, including internal network resources or application secrets, depending on the deployment context (Microsoft MSRC, GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the user interaction requirement. The EPSS score is approximately 0.78%, indicating a low near-term exploitation probability. CVE-2026-62902 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Microsoft MSRC, Feedly).

Exploitation steps

  1. Reconnaissance: Identify applications built on vulnerable .NET versions (8.0.0–8.0.29, 9.0.0–9.0.18, or 10.0.0–10.0.10) or Visual Studio 2022/2026 installations within the target scope.
  2. Craft malicious content: Prepare a malicious file, document, or web resource that, when processed by the vulnerable .NET runtime, causes it to include or reference functionality from an attacker-controlled external source.
  3. Deliver to victim: Socially engineer a target user into opening the malicious content (e.g., via phishing email, malicious link, or shared file), satisfying the required user interaction precondition.
  4. Trigger SSRF/information disclosure: Upon processing, the vulnerable .NET application makes an outbound network request to the attacker-controlled endpoint, potentially leaking sensitive data such as internal tokens, credentials, or application state.
  5. Collect disclosed information: Monitor the attacker-controlled server for incoming requests containing the disclosed information (GitHub Advisory, Microsoft MSRC).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from .NET application processes to external or unusual IP addresses/domains, particularly those not in the application's normal communication baseline.
  • Network: SSRF-pattern requests originating from the application server to internal network resources or metadata endpoints (e.g., cloud instance metadata services).
  • Logs: Application logs showing resolution of or connections to unexpected external hostnames during document or file processing operations.
  • Process: .NET runtime processes (e.g., dotnet.exe) initiating outbound connections to attacker-controlled infrastructure without corresponding user-initiated actions.
  • File System: Presence of unexpected or recently modified configuration files that reference external URIs within .NET application directories (GitHub Advisory).

Mitigation and workarounds

Microsoft has released patches addressing this vulnerability. Users should update to the following fixed versions: .NET 8.0.30 or later, .NET 9.0.19 or later, .NET 10.0.11 or later, Visual Studio 2022 version 17.14.38 or later, and Visual Studio 2026 version 18.8.3 or later. Updates are available via Microsoft Update, Visual Studio's built-in updater, and the .NET download portal. No specific configuration-based workaround has been published; patching is the recommended remediation (Microsoft MSRC, .NET Blog).

Community reactions

The vulnerability was covered as part of broader August 2026 Patch Tuesday reporting, with outlets such as BleepingComputer and GBHackers noting it among approximately 400 flaws addressed in the release. Rapid7 included it in their Patch Tuesday analysis. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been identified, consistent with its medium severity and lack of active exploitation (BleepingComputer, Rapid7).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-pfvm-w89x-94jwHIGH7.5
  • C# logoC#
  • SIPSorcery
NoYesAug 12, 2026
CVE-2026-48798HIGH7.1
  • C# logoC#
  • SSH.NET
NoYesAug 18, 2026
CVE-2026-54570MEDIUM6.9
  • C# logoC#
  • AngleSharp
NoYesAug 18, 2026
CVE-2026-73851MEDIUM6.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesAug 17, 2026
CVE-2026-48796MEDIUM5.3
  • C# logoC#
  • CefSharp.Common
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management