Microsoft.NET Information Disclosure Vulnerability: CVE-2026-62898
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
- Affected component
- microsoft.netcore.app.runtime.win-arm64 (nuget)
- Affected versions
- >= v9.0.18, <= v9.0.18 or >= v8.0.29, <= v8.0.29 or >= v11.0.0-preview.6, <= v11.0.0-preview.6 or >= v10.0.10, <= v10.0.10 or >= v9.0.17, <= v9.0.17 or >= v11.0.0-preview.5, <= v11.0.0-preview.5 or >= v10.0.9, <= v10.0.9 or >= v8.0.28, <= v8.0.28 or >= v11.0.0-preview.4, <= v11.0.0-preview.4 or >= v9.0.16, <= v9.0.16 or >= v8.0.27, <= v8.0.27 or >= v10.0.8, <= v10.0.8 or >= v10.0.7, <= v10.0.7 or >= v11.0.0-preview.3, <= v11.0.0-preview.3 or >= v10.0.6, <= v10.0.6 or >= v9.0.15, <= v9.0.15 or >= v8.0.26, <= v8.0.26 or >= v10.0.5, <= v10.0.5 or >= v9.0.14, <= v9.0.14 or >= v8.0.25, <= v8.0.25 or >= v11.0.0-preview.2, <= v11.0.0-preview.2 or >= v10.0.4, <= v10.0.4 or >= v11.0.0-preview.1, <= v11.0.0-preview.1 or >= v9.0.13, <= v9.0.13 or >= v8.0.24, <= v8.0.24 or >= v10.0.3, <= v10.0.3 or >= v9.0.12, <= v9.0.12 or >= v8.0.23, <= v8.0.23 or >= v10.0.2, <= v10.0.2 or >= v10.0.1, <= v10.0.1 or >= v9.0.11, <= v9.0.11 or >= v8.0.22, <= v8.0.22 or >= v10.0.0, <= v10.0.0
- Patched version
- 10.0.11
An early warning has been issued for a vulnerability in Microsoft.NET runtime that may allow information disclosure. Microsoft.NET projects using certain versions of Microsoft.NETCore.App.Runtime are reportedly affected.
What happened
An early warning has been issued for a use after free vulnerability in Microsoft QUIC that may allow an unauthorized attacker to disclose information over a network. The vulnerability affects Microsoft.NET projects using certain versions of Microsoft.NETCore.App.Runtime. The vulnerability is tracked as CVE-2026-62898 and GHSA-C494-M2FQ-59MX. It has not been exploited in the wild and is not a supply-chain attack.
To assess your exposure, check if your Microsoft.NET projects use the affected versions of Microsoft.NETCore.App.Runtime. The affected versions are listed in the threat data above. If you are using any of these versions, you may be vulnerable to this issue.
What to do about it
- Upgrade to the patched versions: 10.0.11 for.NET 10 and 9.0.19 for.NET 9.
- Check your Microsoft.NET projects for the affected versions of Microsoft.NETCore.App.Runtime and upgrade them to the patched versions.
- Monitor the primary sources for updates on this vulnerability.
How 0Day would have caught this
microsoft.netcore.app.runtime.win-arm64 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if your Microsoft.NET projects use the affected versions of Microsoft.NETCore.App.Runtime. The affected versions are listed in the threat data above.
What should I do right now?
Upgrade to the patched versions: 10.0.11 for.NET 10 and 9.0.19 for.NET 9. Check your Microsoft.NET projects for the affected versions of Microsoft.NETCore.App.Runtime and upgrade them to the patched versions. Monitor the primary sources for updates on this vulnerability.
Has this vulnerability been exploited in the wild?
No, this vulnerability has not been exploited in the wild according to the primary sources.