PT-2026-87350 · Microsoft+1 · .Net 10.0+9

CVE-2026-69304

·

Published

2026-09-08

·

Updated

2026-09-09

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Microsoft's Security Advisory CVE-2026-69304 hits ASP․NET Core, a denial of service vulnerability.
ASP․NET Core's MEV IValidationMessageFormatter is superseded by ValidationAttribute․FormatMessage, which the BCL now provides. The interface gets dropped in favor of the base class method.
F# ships new Task and Async helpers: parallelLimit, parallelDoLimit, and sequential, part of the proposals in fslang-suggestions.
.NET's skills repo adds an NUnit 3/4 to MSTest v4 migration skill, classifying all 48 attributes in NUnit's official attribute index.
The MAUI NuGet config pinning fix shares manifest resolution and feed fallback between commit discovery and workload installation, reading package metadata from the selected feed. The change follows dotnet12 being added, when commit discovery found no mobile manifests there. #dotnet

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69304
GHSA-8CP2-47HG-MFGH

Affected Products

.Net 10.0
.Net 8.0
.Net 9.0
Asp.Net Core 10.0
Asp.Net Core 11.0
Asp.Net Core 8.0
Asp.Net Core 9.0
Visual Studio 2022 Version 17.14
Visual Studio 2026 Version 18.9
Microsoft.Aspnetcore.Server.Iisintegration