FORSMILE
JA
セキュリティ2026/07/27

[URGENT] Microsoft .NET CVE-2026-47304: Apply Security Update — Severe Impact on Confidentiality, Integrity, and Availability

An urgent vulnerability (CVE-2026-47304) affecting Microsoft .NET and Visual Studio has been discovered, allowing unauthenticated attackers to bypass security features. Immediate update to a patched version is mandatory.

Back to Blog

On July 27, 2026, a critical vulnerability (CVE-2026-47304) was publicly disclosed, affecting multiple Microsoft .NET and Visual Studio products. This vulnerability allows unauthenticated remote attackers to bypass security features over a network. It is rated with a CVSS v3 base score of 9.8 (Critical) and poses a severe risk to confidentiality, integrity, and availability. The vulnerability stems from improper cryptographic signature validation, and the immediate application of a security update is strongly recommended.

Immediate Actions Required

  • Update to the patched version confirmed by official sources.
  • Apply official workarounds until the update is available (no official workarounds have been announced yet).
  • Check for signs of compromise.

Vulnerability Overview and Scope of Impact

This vulnerability, CVE-2026-47304, stems from improper cryptographic signature validation (CWE-347) and insufficient verification of data authenticity (CWE-345) in Microsoft .NET. This allows attackers to bypass security features, including authentication mechanisms, over a network and potentially manipulate the system. A wide range of products are affected, including the following versions:

• .NET 10.0.0 and later, up to but not including 10.0.6

• .NET 8.0.0 and later, up to but not including 8.0.29

• .NET 9.0.0 and later, up to but not including 9.0.18

• Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1

• Microsoft Visual Studio 2026 18.7.0 and later, up to but not including 18.7.4, and 18.5.0

• Visual Studio 2017 15.0 through 15.9

• Visual Studio 2019 16.0 through 16.11

• Visual Studio 2022 17.12.0 and later, up to but not including 17.12.22, and 17.14.0 and later, up to but not including 17.14.36

⚠ CVE Score — 最高危険度 / CRITICAL
9.8CRITICALCVE-2026-47304

Specific Impact and Attack Scenarios

If this vulnerability is exploited, an unauthenticated attacker can gain unauthorized access to the target software via the network and bypass security features. This could lead to the leakage or alteration of all information handled by the software. Furthermore, in the worst-case scenario, there is a concern about an impact on availability, potentially leading to a complete service outage. Currently, no specific information regarding "active exploitation" of this vulnerability has been publicly released, but its severity demands immediate action.

Response Procedures and Verification Methods

Promptly apply the security update provided by Microsoft. For detailed instructions, refer to Microsoft's Security Update Guide, and it is crucial to apply the appropriate patch corresponding to your product version. It is also important to verify that your system has been updated and to conduct regular security audits to monitor for any suspicious activity.

📦
Amazon で関連書籍・ツールを検索
cybersecurity server security tools
Amazonで探す →(アソシエイトリンク)

References and Official Patch Information

Related articles