CVE-2026-32226: .NET Framework Denial of Service Vulnerability
.NET Framework Denial of Service Vulnerability
Other sources
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8982 & 3.0.30729.8976Patch KB5082398 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082417 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082425 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082424 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082419 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4141.0Patch KB5082402 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082400 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.4801.0Patch KB5082426 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.4801.0Patch KB5082427 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082420 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0Patch KB5082413 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8982 & 3.0.30729.8976Patch KB5082406 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082418 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0Patch KB5082414 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082404 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082403 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4801.0Patch KB5082411 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0Patch KB5082421
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32226?
CVE-2026-32226 has a high severity rating due to its potential to cause denial of service through improper synchronization.
How do I fix CVE-2026-32226?
To fix CVE-2026-32226, update your .NET Framework to the latest patched version provided by Microsoft.
Which versions of .NET Framework are affected by CVE-2026-32226?
CVE-2026-32226 affects .NET Framework versions 3.5, 4.7.2, 4.8, and 4.8.1.
Can CVE-2026-32226 be exploited remotely?
Yes, CVE-2026-32226 allows an unauthorized attacker to exploit the vulnerability remotely over a network.
What type of vulnerability is CVE-2026-32226?
CVE-2026-32226 is categorized as a Denial of Service vulnerability resulting from a race condition.