CVE-2026-62900: .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability
Other sources
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.19Patch KB5122105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.30Patch KB5122104 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.11Patch KB5122106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.38 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62900?
The severity of CVE-2026-62900 is classified as medium with a score of 5.9.
What does CVE-2026-62900 exploit?
CVE-2026-62900 exploits improper removal of sensitive information before storage or transfer in .NET.
How do I fix CVE-2026-62900?
To fix CVE-2026-62900, update to the latest version of Microsoft .NET provided by Microsoft.
Which software versions are affected by CVE-2026-62900?
CVE-2026-62900 affects Microsoft .NET 8.0, 9.0, and 10.0, as well as Microsoft Visual Studio 2022 across various operating systems.
What impact does CVE-2026-62900 have?
CVE-2026-62900 allows unauthorized attackers to disclose sensitive information over a network.