HomeCVE Intelligence › CVE-2026-50524
CVSS 7.5 HIGH Vulnerability

CVE-2026-50524: Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability

Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to updat…

7.5CVSS Score
HIGHSeverity
NOCISA KEV
0.6%EPSS Score
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-50524
Vendornuget
Affected ProductMicrosoft.NetCore.App.Runtime.linux-arm
Vulnerability TypeVulnerability
CVSS Score7.5 (HIGH)
EPSS Score0.6% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories)

🔬 Technical Analysis

#

Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 when processing TLS handshakes. An attacker can send a malformed request and cause application to crash or become unresponsive.

Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/TBD

CVSS Details - Version: 3.1

Severity: High
Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
Weakness: CWE-1287 (Improper Validation of Specified Type

🎯 Known Indicators of Compromise

{"type":"url","value":"https://github.com/dotnet/announcements/issues/**TBD**","confidence_score":0.82,"first_seen":"2026-07-20","source_count":1} {"type":"domain","value":"system.net","confidence_score":0.75,"first_seen":"2026-07-20","source_count":1}

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-50524 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence