Microsoft · .Net Framework · CVE-2026-33116
**Name of the Vulnerable Software and Affected Versions**
System.Security.Cryptography.Xml versions 10.0.0 through 10.0.5
System.Security.Cryptography.Xml versions 9.0.0 through 9.0.14
System.Security.Cryptography.Xml versions 8.0.0 through 8.0.2
.NET (affected versions not specified)
.NET Framework (affected versions not specified)
Visual Studio (affected versions not specified)
**Description**
An issue exists in the `EncryptedXml` class where an unauthorized attacker can cause an infinite loop, which is a loop with an unreachable exit condition. This can be exploited over a network to perform a Denial of Service attack, causing the system to become unavailable.
**Recommendations**
Update System.Security.Cryptography.Xml versions 10.0.0 through 10.0.5 to version 10.0.6.
Update System.Security.Cryptography.Xml versions 9.0.0 through 9.0.14 to version 9.0.15.
Update System.Security.Cryptography.Xml versions 8.0.0 through 8.0.2 to version 8.0.3.