
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62902 is an information disclosure vulnerability in Microsoft .NET caused by inclusion of functionality from an untrusted control sphere (CWE-829), effectively enabling Server-Side Request Forgery (SSRF) conditions. It was disclosed on August 11, 2026, as part of Microsoft's August 2026 Patch Tuesday release. Affected products include .NET 8.0 (versions 8.0.0–8.0.29), .NET 9.0 (versions 9.0.0–9.0.18), .NET 10.0 (versions 10.0.0–10.0.10), Microsoft Visual Studio 2022 version 17.14 (before 17.14.38), and Microsoft Visual Studio 2026 version 18.8 (before 18.8.3). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Microsoft MSRC, Feedly).
The root cause is classified under CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), CWE-693 (Protection Mechanism Failure), and CWE-918 (Server-Side Request Forgery). The vulnerability allows .NET to load or reference functionality from an attacker-controlled or untrusted source, which can be leveraged to cause the application to make network requests that disclose sensitive information to an unauthorized party. Exploitation requires user interaction (e.g., a victim opening a malicious file or visiting a crafted page), but no authentication or elevated privileges are needed on the attacker's side. No public proof-of-concept code has been identified at this time (Microsoft MSRC, GitHub Advisory).
Successful exploitation results in high confidentiality impact — sensitive information can be disclosed over the network to an unauthenticated attacker. Integrity and availability are not affected. The SSRF-like nature of the flaw means an attacker could potentially cause the vulnerable .NET application to exfiltrate data to an external server, including internal network resources or application secrets, depending on the deployment context (Microsoft MSRC, GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the user interaction requirement. The EPSS score is approximately 0.78%, indicating a low near-term exploitation probability. CVE-2026-62902 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Microsoft MSRC, Feedly).
dotnet.exe) initiating outbound connections to attacker-controlled infrastructure without corresponding user-initiated actions.Microsoft has released patches addressing this vulnerability. Users should update to the following fixed versions: .NET 8.0.30 or later, .NET 9.0.19 or later, .NET 10.0.11 or later, Visual Studio 2022 version 17.14.38 or later, and Visual Studio 2026 version 18.8.3 or later. Updates are available via Microsoft Update, Visual Studio's built-in updater, and the .NET download portal. No specific configuration-based workaround has been published; patching is the recommended remediation (Microsoft MSRC, .NET Blog).
The vulnerability was covered as part of broader August 2026 Patch Tuesday reporting, with outlets such as BleepingComputer and GBHackers noting it among approximately 400 flaws addressed in the release. Rapid7 included it in their Patch Tuesday analysis. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been identified, consistent with its medium severity and lack of active exploitation (BleepingComputer, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."