CVE-2026-21218Improper Handling of Missing Special Element in Microsoft NET 10.0

Severity
7.5HIGHNVD
EPSS
0.0%
top 86.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10
Latest updateFeb 16

Description

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDmicrosoft/net8.0.08.0.24+2
CVEListV5microsoft/net_8.08.0.08.0.24
CVEListV5microsoft/net_9.09.0.09.0.13
CVEListV5microsoft/net_10.010.0.010.0.3

🔴Vulnerability Details

4
GHSA
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability2026-02-10
OSV
CVE-2026-21218: Improper handling of missing special element in2026-02-10
OSV
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability2026-02-10
CVEList
.NET Spoofing Vulnerability2026-02-10

📋Vendor Advisories

3
Ubuntu
.NET vulnerability2026-02-16
Ubuntu
.NET vulnerability2026-02-11
Microsoft
.NET Spoofing Vulnerability2026-02-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-21218 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-21218 — Microsoft NET 10.0 vulnerability | cvebase