Security update fixing 14 CVEs

0Windows versions
14CVEs fixed · 0 critical
0Exploited or in CISA KEV
0Open known issues affecting it
—Restart required (per MSRC)

Known issues in this update

Windows release health

No known issues listed

Windows release health lists no issues from this KB or the update it builds on.

Issues this update resolves

No resolved issues listed

Windows release health names no issues fixed by this KB.

Security fixes

14 Microsoft CVEs · most urgent first
CVE Vulnerability Severity CVSSEPSSImpact Status
CVE-2026-47300 ASP.NET Core Elevation of Privilege VulnerabilityASP.NET Core Important 8.80.8%Elevation of Privilege
CVE-2026-47303 ASP.NET Core Elevation of Privilege VulnerabilityASP.NET Core Important 8.80.8%Elevation of Privilege Revised 7 Aug
CVE-2026-50528 .NET Security Feature Bypass Vulnerability.NET Important 8.20.6%Security Feature Bypass
CVE-2026-47304 .NET Security Feature Bypass Vulnerability.NET Important 8.10.3%Security Feature Bypass Revised 21 Jul
CVE-2026-47302 .NET Denial of Service Vulnerability.NET Important 7.51.2%Denial of Service Revised 20 Jul
CVE-2026-50524 .NET Framework Denial of Service Vulnerability.NET Framework Important 7.51.2%Denial of Service
CVE-2026-50525 .NET Denial of Service Vulnerability.NET Important 7.51.2%Denial of Service Revised 21 Jul
CVE-2026-50527 .NET Framework Denial of Service Vulnerability.NET Framework Important 7.51.2%Denial of Service Revised 20 Jul
CVE-2026-50648 .NET Framework Denial of Service Vulnerability.NET Framework Important 7.51.2%Denial of Service Revised 20 Jul
CVE-2026-50651 .NET Denial of Service Vulnerability.NET Important 7.51.2%Denial of Service
CVE-2026-56170 ASP.NET Core Denial of Service VulnerabilityASP.NET Core Important 7.51.2%Denial of Service
CVE-2026-57108 .NET Denial of Service Vulnerability.NET Core Important 7.51.2%Denial of Service
CVE-2026-50526 .NET Tampering Vulnerability.NET Important 7.00.2%Tampering
CVE-2026-50659 .NET Spoofing Vulnerability.NET Important 6.50.7%Spoofing Revised 7 Aug
ChangeIntel is an independent tool and is not affiliated with or endorsed by Microsoft. Microsoft, Windows, Microsoft 365, Azure, and related names are trademarks of the Microsoft group of companies. Data comes from public sources listed on Sources; every item links to its original page. Dates and statuses can change after they are read. Built by Evotec. This is the public demo. It can also run on your own server, with your Microsoft 365 tenant and device data kept inside your network; Evotec can help you deploy and extend it.