A high-severity vulnerability affecting Microsoft.NETCore.App.Runtime.win-arm64 versions >= 10.0.0, <= 10.0.10 affecting Microsoft.NETCore.App.Runtime.win-x64 versions >= 10.0.0, <= 10.0.10 (CVE-2026-62898) with a CVSS score of 7.5 has been identified in Microsoft QUIC, allowing an unauthorized attacker to disclose information over a network through a use after free flaw. This issue affects any Microsoft.NET project that uses affected package versions, specifically impacting confidentiality with high impact. The vulnerability can be exploited via the environment template management API for remote code execution. Affected platforms include Windows across all architectures, and impacted versions of the Microsoft.NETCore.App.Runtime package range from 8.0.0 to 10.0.10. To address this issue, developers should update their applications by installing the latest version of.NET, updating package references to patched versions, and recompiling and redeploying self-contained applications targeting affected versions.
We recommend you to update Microsoft .NET to version 10.0.11, 9.0.19, or 8.0.30.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting Microsoft.NETCore.App.Runtime.win-arm64 versions >= 10.0.0, <= 10.0.10 affecting Microsoft.NETCore.App.Runtime.win-x64 versions >= 10.0.0, <= 10.0.10 (CVE-2026-62898) with a CVSS score of 7.5 has been identified in Microsoft QUIC, allowing an unauthorized attacker to disclose information over a network through a use after free flaw. This issue affects any Microsoft.NET project that uses affected package versions, specifically impacting confidentiality with high impact. The vulnerability can be exploited via the environment template management API for remote code execution. Affected platforms include Windows across all architectures, and impacted versions of the Microsoft.NETCore.App.Runtime package range from 8.0.0 to 10.0.10. To address this issue, developers should update their applications by installing the latest version of.NET, updating package references to patched versions, and recompiling and redeploying self-contained applications targeting affected versions.
We recommend you to update Microsoft .NET to version 10.0.11, 9.0.19, or 8.0.30.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]