CVE-2026-50355 – Microsoft .NET Framework 3.5

CVSS 7.5 IMPORTANT High with EoP or RCE – Expedited Deployment

“Even mature application frameworks require continuous hardening to keep trust and execution boundaries intact.”

Microsoft has released security updates for .NET Framework 3.5 to address six High severity vulnerabilities affecting authentication validation, memory safety, and resource management. The updates strengthen the framework against memory corruption, denial-of-service conditions, and validation weaknesses that could be leveraged to compromise applications built on affected .NET Framework deployments.

CVE-2026-47304 has a CVSS score of 8.1, High severity. CVE-2026-50304 has a CVSS score of 7.5, High severity. CVE-2026-50355 has a CVSS score of 7.5, High severity. CVE-2026-50368 has a CVSS score of 7.5, High severity. CVE-2026-50411 has a CVSS score of 7.5, High severity. CVE-2026-50647 has a CVSS score of 7.5, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Microsoft Windows 10 1607
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-121
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.