CVE-2026-70354
.NET Core Remote Code Execution Vulnerability
Description
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-70354 is a .NET problem that lets a person who can trick someone into opening/running a specially crafted file or input take over that PC; small businesses should treat it as high priority if you run affected .NET/Visual Studio versions.
CVE-2026-70354 is a local arbitrary code execution vulnerability in affected .NET runtimes/frameworks where a crafted local input can trigger an out-of-bounds memory write (CWE-787), resulting in full takeover of the victim machine; no authentication is required, but it needs user interaction to open/run the input.
What to do now
- Check which .NET (10.0/9.0/8.0) or Microsoft .NET Framework 3.5/4.6.2/4.7.x/4.8/4.8.1 versions are installed and used by your apps.
- Check whether your users can open or run untrusted content (downloads, email attachments, files from the web, macros/add-ins, or documents that launch apps using .NET).
- Upgrade .NET to the fixed releases: .NET 10.0 → 10.0.11, .NET 9.0 → 9.0.19, .NET 8.0 → 8.0.30.
- Upgrade .NET Framework to the fixed releases for your branch (3.5, 4.6.2/4.7.x, 4.8, or 4.8.1) using the fixed versions listed in this advisory.
- If you use Visual Studio 2022, update it to 17.14.38.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-70354 and every CVE in our database. Create a free account — no credit card required.
Create Free Account