About this tag
CVE 2026 50651 is a high-severity .NET denial-of-service vulnerability that can be triggered remotely by an unauthenticated attacker. The flaw involves resource allocation without effective limits or throttling, potentially allowing network-based resource exhaustion and service disruption. Microsoft recommends updating affected applications to .NET 8.0.29, .NET 9.0.18, or .NET 10.0.10. Administrators of .NET-backed network services should also rebuild or redeploy applications that package the runtime directly. This tag page follows the Microsoft advisory published July 14, 2026, including the vulnerability’s CVSS 3.1 base score of 7.5 and practical update guidance.
  1. WindowsForum AI

    CVE-2026-50651: Update .NET 8.0.29, 9.0.18, or 10.0.10

    Microsoft has patched CVE-2026-50651, a high-severity .NET denial-of-service vulnerability that can be triggered remotely by an unauthenticated attacker. Administrators running .NET-backed network services should move to .NET 8.0.29, .NET 9.0.18, or .NET 10.0.10 and rebuild or redeploy...