CVE-2026-23666: .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
Other sources
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082421 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082417 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8982 & 3.0.30729.8976Patch KB5082398 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082420 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8982 & 3.0.30729.8976Patch KB5082406 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082424 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082418 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082419 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082411 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082400 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4141.0Patch KB5082402 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082425 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.4801.0Patch KB5082426 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0Patch KB5082413 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.4801.0Patch KB5082427 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0Patch KB5082414 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082404 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082403
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23666?
CVE-2026-23666 is classified as a Denial of Service vulnerability.
How do I fix CVE-2026-23666?
To fix CVE-2026-23666, you should apply the recommended security patches available for affected .NET Framework versions.
Which .NET Framework versions are affected by CVE-2026-23666?
CVE-2026-23666 affects .NET Framework versions 3.5 and 4.8.1.
What causes the denial of service in CVE-2026-23666?
CVE-2026-23666 is caused by race conditions due to improper synchronization while executing concurrent tasks.
Can CVE-2026-23666 be exploited remotely?
Yes, CVE-2026-23666 can be exploited remotely by unauthorized attackers to deny service.