CVE Tools

CVE-2026-62898

Microsoft QUIC Information Disclosure Vulnerability

Published: Aug 11, 2026Updated: Aug 14, 2026 Sources: CVE List NVDCWE-416

Description

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

In plain language

AI Act now

This is a .NET/Visual Studio QUIC network bug where a remote attacker could read confidential data without logins; if you use Microsoft QUIC with affected versions, you should fix it now (priority is high).

Executive summary

Use-after-free in Microsoft QUIC allows an unauthenticated remote attacker to trigger an information disclosure over the network by causing freed memory to be re-used during QUIC processing.

If affected, business impact
Confidential data exposureCustomer or user data leakagePotential legal/privacy riskService trust damage

What to do now

  1. Check whether your organization is running affected versions of .NET (8.0, 9.0, 10.0) or Visual Studio (2022 17.14 / 2026 18.8) that include Microsoft QUIC.
  2. Identify whether Microsoft QUIC is in use on your externally reachable services (for example, any server components using QUIC/HTTP3). If you are unsure, confirm with your app/platform team.
  3. Upgrade to the fixed versions: .NET 10.0 → 10.0.11, .NET 8.0 → 8.0.30, .NET 9.0 → 9.0.19, Microsoft Visual Studio 2022 version 17.14 → 17.14.38, Microsoft Visual Studio 2026 version 18.8 → 18.8.3.
  4. After upgrading, retest that your QUIC-enabled services still start normally and that your web/app behavior is unchanged.
  5. If you cannot upgrade immediately, disable or remove QUIC usage for any internet-facing services until patched (ask your platform vendor/app team how to do this safely for your setup).
dotnet tool update --global dotnet-dev-certs
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:NA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-62898 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows