CVE-2026-70354: .NET Core Remote Code Execution Vulnerability
.NET Core Remote Code Execution Vulnerability
Other sources
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0Patch KB5120418 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8984 & 3.0.30729.8980Patch KB5120716 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8984 & 3.0.30729.8980Patch KB5120695 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169Patch KB5120747 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9344.0Patch KB5120711 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4805.0Patch KB5120706 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4144.0Patch KB5120699 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120713 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0Patch KB5120708 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120710 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.19Patch KB5122105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.30Patch KB5122104 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0Patch KB5120698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0Patch KB5120703 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.11Patch KB5122106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.38 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4805.0Patch KB5120702 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4805.0Patch KB5120704 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120709 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4144.0Patch KB5120700 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0Patch KB5120701 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0Patch KB5120714 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0Patch KB5120705
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70354?
CVE-2026-70354 has a high severity rating of 7.8.
How do I fix CVE-2026-70354?
To fix CVE-2026-70354, apply the latest security updates for the affected .NET versions provided by Microsoft.
What software is affected by CVE-2026-70354?
CVE-2026-70354 affects Microsoft .NET 8.0, 9.0, and 10.0 across various operating systems including Windows, Mac OS, and Linux.
What type of vulnerability is CVE-2026-70354?
CVE-2026-70354 is a remote code execution vulnerability due to an out-of-bounds write in .NET.
Who can exploit CVE-2026-70354?
An unauthorized attacker can exploit CVE-2026-70354 to execute code locally on vulnerable systems.