CVE-2026-62900
.NET Information Disclosure Vulnerability
Description
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
In plain language
AI Act nowThis is a .NET flaw that can let an attacker over the network view sensitive private data, and most small businesses using the affected .NET/Visual Studio components should take action to upgrade.
CVE-2026-62900 is an information disclosure weakness (CWE-212) in .NET that allows an unauthenticated, network-reachable attacker to steal sensitive data intended for the target system by triggering improper handling/removal of sensitive information before storage or transfer.
What to do now
- Check whether your systems use the affected .NET and/or Microsoft Visual Studio components, and whether they are on versions earlier than the fixed releases.
- Upgrade .NET to version 8.0.30 (and also to 9.0.19 or 10.0.11 if you use those lines).
- Upgrade Visual Studio 2022 to 17.14.38 (and Visual Studio 2026 to 18.8.3).
- If you can’t upgrade immediately, restrict network access to any services using the vulnerable .NET component until patching is complete.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62900 and every CVE in our database. Create a free account — no credit card required.
Create Free Account