NUGET · AUGUST 2026 · EARLY WARNING

Microsoft.NET Information Disclosure Vulnerability: CVE-2026-62898

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Affected component
microsoft.netcore.app.runtime.win-arm64 (nuget)
Affected versions
>= v9.0.18, <= v9.0.18 or >= v8.0.29, <= v8.0.29 or >= v11.0.0-preview.6, <= v11.0.0-preview.6 or >= v10.0.10, <= v10.0.10 or >= v9.0.17, <= v9.0.17 or >= v11.0.0-preview.5, <= v11.0.0-preview.5 or >= v10.0.9, <= v10.0.9 or >= v8.0.28, <= v8.0.28 or >= v11.0.0-preview.4, <= v11.0.0-preview.4 or >= v9.0.16, <= v9.0.16 or >= v8.0.27, <= v8.0.27 or >= v10.0.8, <= v10.0.8 or >= v10.0.7, <= v10.0.7 or >= v11.0.0-preview.3, <= v11.0.0-preview.3 or >= v10.0.6, <= v10.0.6 or >= v9.0.15, <= v9.0.15 or >= v8.0.26, <= v8.0.26 or >= v10.0.5, <= v10.0.5 or >= v9.0.14, <= v9.0.14 or >= v8.0.25, <= v8.0.25 or >= v11.0.0-preview.2, <= v11.0.0-preview.2 or >= v10.0.4, <= v10.0.4 or >= v11.0.0-preview.1, <= v11.0.0-preview.1 or >= v9.0.13, <= v9.0.13 or >= v8.0.24, <= v8.0.24 or >= v10.0.3, <= v10.0.3 or >= v9.0.12, <= v9.0.12 or >= v8.0.23, <= v8.0.23 or >= v10.0.2, <= v10.0.2 or >= v10.0.1, <= v10.0.1 or >= v9.0.11, <= v9.0.11 or >= v8.0.22, <= v8.0.22 or >= v10.0.0, <= v10.0.0
Patched version
10.0.11
CVE-2026-62898GHSA-C494-M2FQ-59MX

An early warning has been issued for a vulnerability in Microsoft.NET runtime that may allow information disclosure. Microsoft.NET projects using certain versions of Microsoft.NETCore.App.Runtime are reportedly affected.

What happened

An early warning has been issued for a use after free vulnerability in Microsoft QUIC that may allow an unauthorized attacker to disclose information over a network. The vulnerability affects Microsoft.NET projects using certain versions of Microsoft.NETCore.App.Runtime. The vulnerability is tracked as CVE-2026-62898 and GHSA-C494-M2FQ-59MX. It has not been exploited in the wild and is not a supply-chain attack.

To assess your exposure, check if your Microsoft.NET projects use the affected versions of Microsoft.NETCore.App.Runtime. The affected versions are listed in the threat data above. If you are using any of these versions, you may be vulnerable to this issue.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If microsoft.netcore.app.runtime.win-arm64 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if your Microsoft.NET projects use the affected versions of Microsoft.NETCore.App.Runtime. The affected versions are listed in the threat data above.

What should I do right now?

Upgrade to the patched versions: 10.0.11 for.NET 10 and 9.0.19 for.NET 9. Check your Microsoft.NET projects for the affected versions of Microsoft.NETCore.App.Runtime and upgrade them to the patched versions. Monitor the primary sources for updates on this vulnerability.

Has this vulnerability been exploited in the wild?

No, this vulnerability has not been exploited in the wild according to the primary sources.

Sources

Join the 0Day waitlist →

← Back to all threats