NUGET · SEPTEMBER 2026 · EARLY WARNING

Microsoft QUIC Vulnerability: Critical CVE-2026-62815 Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
Microsoft.Native.Quic.MsQuic.OpenSSL (nuget)
Affected versions
< 2.1.12 or >= 1.8.0, <= 1.8.0 or >= 2.2.0, < 2.2.7 or >= 2.3.0, < 2.3.5 or < 2.2.3 or >= 1.8.0, <= 1.8.0 or >= 2.5.0-ci.532574, < 2.5.7 or < 2.4.18 or >= 1.8.0, <= 1.8.0 or < 2.2.3 or >= 1.8.0, <= 1.8.0
Patched version
e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b
GHSA-92F5-VC22-8J33

An early warning has been issued for a critical vulnerability in Microsoft QUIC that could allow remote code execution. Users of affected versions of Microsoft.Native.Quic.MsQuic.OpenSSL and Microsoft.Native.Quic.MsQuic.Schannel are urged to assess their exposure.

What happened

A critical vulnerability, tracked as CVE-2026-62815, has been identified in Microsoft QUIC. This use after free vulnerability reportedly allows an unauthorized attacker to execute code over a network. Successful exploitation could enable the attacker to execute code on the target system. The vulnerability affects specific versions of Microsoft.Native.Quic.MsQuic.OpenSSL and Microsoft.Native.Quic.MsQuic.Schannel.

The vulnerability was first flagged on 2026-09-08T20:27:02+00:00. It is currently under investigation and has not been exploited in the wild. The affected components and version ranges are detailed in the threat data. Users are advised to consult the primary sources for the most accurate and up-to-date information.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If Microsoft.Native.Quic.MsQuic.OpenSSL is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using Microsoft.Native.Quic.MsQuic.OpenSSL or Microsoft.Native.Quic.MsQuic.Schannel in the specified version ranges. Consult the threat data for the exact versions.

What should I do right now?

Immediately assess if your systems are using affected versions. Upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b and monitor the primary sources for updates.

Is there an official fix available?

Yes, the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b is available for both affected components.

Sources

Join the 0Day waitlist →

← Back to all threats