NUGET · SEPTEMBER 2026 · EARLY WARNING

Microsoft QUIC Remote Code Execution Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
microsoft quic (nuget)
Patched version
e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b
GHSA-92F5-VC22-8J33

An early warning has been issued for a critical remote code execution vulnerability in Microsoft QUIC. This vulnerability could allow an unauthorized attacker to execute code over a network.

What happened

An early warning has been issued for a critical remote code execution vulnerability in Microsoft QUIC. This vulnerability, tracked as GHSA-92F5-VC22-8J33 and CVE-2026-62815, reportedly allows an unauthorized attacker to execute code over a network. Successful exploitation could allow the attacker to execute code on the target system. The vulnerability was first flagged on September 8, 2026. It is not yet confirmed if this vulnerability has been exploited in the wild.

The affected component is Microsoft QUIC (nuget). The specific version range of affected versions is not yet authoritatively published, but the patched version is e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b. Users are advised to upgrade to this patched version to mitigate the risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If microsoft quic is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

The specific version range of affected versions is not yet authoritatively published. However, if you are using Microsoft QUIC (nuget), it is recommended to upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b.

What should I do right now?

Upgrade to the patched version e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b of Microsoft QUIC (nuget) and monitor the primary sources for updates.

Where can I find more information about this vulnerability?

Consult the primary sources: [GHSA-92f5-vc22-8j33] Microsoft QUIC: Remote Code Execution Vulnerability (https://github.com/advisories/GHSA-92f5-vc22-8j33) and [GHSA-92f5-vc22-8j33] Microsoft QUIC: Remote Code Execution Vulnerability (https://github.com/microsoft/msquic/security/advisories/GHSA-92f5-vc22-8j33).

Sources

Join the 0Day waitlist →

← Back to all threats