CVE-2026-62872
published 2026-08-11CVE-2026-62872: Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
PriorityP258high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.54%
43.4th percentile
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_3.5 | >= 3.5.0 < 2.0.50727.9183 & 3.0.30729.9169 | 2.0.50727.9183 & 3.0.30729.9169 |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | >= 3.0.0.0 < 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0 | 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0 |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0 | 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0 |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0 | 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0 |
| microsoft | microsoft_net_framework_3.5_and_4.8.1 | >= 4.8.1 < 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 | 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.4144.0 | 4.7.4144.0 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.4805.0 | 4.8.4805.0 |
| microsoft | microsoft_net_framework_4.8.1 | >= 4.8.0.0 < 4.8.9344.0 | 4.8.9344.0 |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft .NET Framework improper authorization (WID-SEC-2026-2761)
vuldb·2026-08-15·CVSS 8.8
CVE-2026-62872 [HIGH] Microsoft .NET Framework improper authorization (WID-SEC-2026-2761)
A vulnerability was found in Microsoft .NET Framework. It has been declared as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improper authorization.
This vulnerability is handled as CVE-2026-62872. The attack can be executed remotely. There is not any exploit available.
Applying a patch is advised to resolve this issue.
GHSA
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
ghsa_unreviewed·2026-08-11
CVE-2026-62872 [HIGH] CWE-863 Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
Red Hat
dotnet: .NET Framework: Elevation of Privilege via incorrect authorization
vendor_redhat·2026-08-11·CVSS 8.8
CVE-2026-62872 [HIGH] CWE-266 dotnet: .NET Framework: Elevation of Privilege via incorrect authorization
dotnet: .NET Framework: Elevation of Privilege via incorrect authorization
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
A flaw was found in .NET Framework. An authorized attacker could exploit incorrect authorization over a network to elevate their privileges.
Statement: Red Hat ships cross-platform .NET runtimes (dotnet 8.0, 9.0, 10.0) on Linux. The .NET Framework runtime affected by this vulnerability is a Windows-only product distributed via Windows Update, which Red Hat has never shipped. The vulnerable code is not present in any Red Hat product.
Mitigation: No mitigation is required. Red Hat does not ship the Windows-only .NET Framework runtime.
Package: dotnet10.0 (Red Hat Enterprise Linux 10) - Not affected
Packa
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Bugzilla
CVE-2026-62872 dotnet: .NET Framework: Elevation of Privilege via incorrect authorization
bugzilla·2026-08-11·CVSS 8.8
CVE-2026-62872 [HIGH] CVE-2026-62872 dotnet: .NET Framework: Elevation of Privilege via incorrect authorization
CVE-2026-62872 dotnet: .NET Framework: Elevation of Privilege via incorrect authorization
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
2026-08-11
Published