Threat Advisory

NET Denial of Service Vulnerability Allows Attackers to Cause Denial

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Microsoft.NetCore.App.Runtime.linux-arm versions >= 8.0.0, <= 8.0.28 affecting Microsoft.NetCore.App.Runtime.linux-arm64 versions >= 8.0.0, <= 8.0.28 affecting Microsoft.NetCore.App.Runtime.linux-arm versions >= 9.0.0, <= 9.0.17 affecting Microsoft.NetCore.App.Runtime.linux-arm64 versions >= 9.0.0, <= 9.0.17 have been identified in Microsoft.NET projects that use affected package versions. The overall risk and impact are significant, allowing attackers to cause denial-of-service attacks. Affected version ranges include >= 10.0.0, <= 10.0.9 for Linux and macOS platforms.

CVE-2026-57108 (CVSS 7.5 — High): A denial of service vulnerability exists in the.NET runtime when parsing X.509 certificates. An attacker could cause a specially crafted certificate to allow a denial-of-service attack.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Microsoft.NetCore.App.Runtime.linux-arm versions >= 8.0.0, <= 8.0.28 affecting Microsoft.NetCore.App.Runtime.linux-arm64 versions >= 8.0.0, <= 8.0.28 affecting Microsoft.NetCore.App.Runtime.linux-arm versions >= 9.0.0, <= 9.0.17 affecting Microsoft.NetCore.App.Runtime.linux-arm64 versions >= 9.0.0, <= 9.0.17 have been identified in Microsoft.NET projects that use affected package versions. The overall risk and impact are significant, allowing attackers to cause denial-of-service attacks. Affected version ranges include >= 10.0.0, <= 10.0.9 for Linux and macOS platforms.

CVE-2026-57108 (CVSS 7.5 — High): A denial of service vulnerability exists in the.NET runtime when parsing X.509 certificates. An attacker could cause a specially crafted certificate to allow a denial-of-service attack.[emaillocker id="1283"]

CVE-2026-50524 (CVSS 7.5 — High): SCOPE: Severity, CVSS, CWE, and description in this block apply ONLY to

CVE-2026-50528 (CVSS 8.2 — High): SCOPE: Severity, CVSS, CWE, and description in this block apply ONLY to

CVE-2026-50651: SCOPE: Severity, CVSS, CWE, and description in this block apply ONLY to

CVE-2026-50659 (CVSS 6.5 — Medium): SCOPE: Severity, CVSS, CWE, and description in this block apply ONLY to These vulnerabilities collectively present a significant risk, and administrators should review their exposure and apply updates to remove the vulnerability. These vulnerabilities collectively present a significant risk, and administrators should review their exposure and apply updates to remove the vulnerability.

These vulnerabilities collectively present a significant risk, and administrators should review their exposure and apply updates to remove the vulnerability. These vulnerabilities collectively present a significant risk, and administrators should review their exposure and apply updates to remove the vulnerability.

RECOMMENDATION:

We recommend you to update .NET to version 10.0.10, 9.0.18, or 8.0.29 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu