CVE-2026-62902
.NET Information Disclosure Vulnerability
Description
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
In plain language
AI Act nowCVE-2026-62902 is a .NET/Visual Studio issue that can let an attacker steal confidential data over the network, but it requires your business/user to interact with the affected app and for the app to load untrusted external functionality—still, you should update because it’s a newly reported, high-priority patch.
CVE-2026-62902 is an information disclosure issue in .NET/Visual Studio where untrusted external sources can be incorporated into .NET functionality, enabling remote confidential data disclosure (no authentication; network accessible) after user interaction.
What to do now
- Check which of these you’re running: Visual Studio 2022 (17.14.x), Visual Studio 2026 (18.8.x), and your installed .NET runtime version (8.0.x or 9.0.x).
- If you are on Visual Studio 2022, upgrade to 17.14.38 or later.
- If you are on Visual Studio 2026, upgrade to 18.8.3 or later.
- If you are on .NET 8.0 (8.0.x), upgrade to 8.0.30 or later.
- If you are on .NET 9.0 (9.0.x), upgrade to 9.0.19 or later.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62902 and every CVE in our database. Create a free account — no credit card required.
Create Free Account