PT-2026-58718 · Microsoft+2 · .Net Framework+3

CVE-2026-50649

·

Published

2026-07-14

·

Updated

2026-08-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions .NET (affected versions not specified) Microsoft Visual Studio (affected versions not specified)
Description An issue exists in the deserialization mechanism of .NET and Microsoft Visual Studio. Deserialization is the process of converting a stream of bytes back into an object. This flaw allows an unauthorized attacker to execute arbitrary code locally by providing untrusted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:41893
ALSA-2026:41894
ALSA-2026:41895
ALSA-2026:41896
ALSA-2026:41897
ALSA-2026:41898
ALSA-2026:41899
ALSA-2026:41900
ALSA-2026:41901
BDU:2026-09808
BIT-DOTNET-2026-50649
BIT-DOTNET-SDK-2026-50649
CVE-2026-50649
RHSA-2026:27171

Affected Products

.Net Framework
Red Os
Rocky Linux
Visual Studio