// OSSeva Blog
Security.NET Vulnerabilities by Version: CVEs for .NET 6, 7, 8, 9 and 10
The short answer
Microsoft supports three .NET lines. .NET 10 is a long-term support release, supported until 14 November 2028. .NET 8, also LTS, and .NET 9, a standard-term release, are both supported until 10 November 2026, because Microsoft gives LTS releases three years and STS releases two. .NET 7 ended on 14 May 2024 and .NET 6 on 12 November 2024. Microsoft's release metadata lists 45 CVEs fixed in .NET 8 releases so far in 2026, 47 in .NET 9 and 49 in .NET 10. Microsoft does not assess .NET 6 or 7 for new CVEs: since their last releases it has fixed 55 CVEs in .NET 8 that came after 6.0.36, and 65 that came after 7.0.20. On 10 November 2026, .NET 8 and 9 join them.
.NET release lines and their CVEs
Dates, support phases and CVE lists are from Microsoft's .NET release metadata, which backs the .NET support policy page and the release notes in the dotnet/core repository.
| Line | Type and status | Latest release | CVEs fixed on this line in 2026 | Upstream fix on this line |
|---|---|---|---|---|
| .NET 10 | LTS; supported until 14 November 2028 | 10.0.12, 8 September 2026 | 49 | All 49, by 10.0.12 |
| .NET 9 | STS; supported until 10 November 2026 | 9.0.20, 8 September 2026 | 47 | All 47, by 9.0.20 |
| .NET 8 | LTS; supported until 10 November 2026 | 8.0.31, 8 September 2026 | 45 | All 45, by 8.0.31 |
| .NET 7 | STS; ended 14 May 2024 | 7.0.20, 28 May 2024 | Not assessed; 65 CVEs fixed in .NET 8 since 7.0.20 | No upstream fix on this line |
| .NET 6 | LTS; ended 12 November 2024 | 6.0.36, 12 November 2024; last security fixes in 6.0.35 | Not assessed; 55 CVEs fixed in .NET 8 since 6.0.36 | No upstream fix on this line |
| .NET 5 and .NET Core 3.1 | Ended 10 May 2022 and 13 December 2022 | 5.0.17; 3.1.32 | Not assessed | No upstream fix on these lines |
"Not assessed" means Microsoft's advisories for these CVEs list .NET 8, 9 and 10 and say nothing about the older lines. It does not mean they are safe. Not every CVE applies to every application: some are in ASP.NET Core components such as Kestrel, SignalR or Negotiate authentication, some only in the Windows Desktop runtime or Windows builds, and some only in the SDK. See the .NET end of life tracker for every line.
Notable .NET CVEs by release line
CVSS is NVD's own score where NVD has scored the record, otherwise Microsoft's score as the CNA. Two .NET CVEs are in CISA's Known Exploited Vulnerabilities catalogue, CVE-2023-38180, added on 9 August 2023, and CVE-2023-44487, the HTTP/2 Rapid Reset flaw, added on 10 October 2023. Both were fixed on .NET 6 and 7 before they ended.
| CVE | Issue | CVSS | Fixed in | Lines with no fix |
|---|---|---|---|---|
| CVE-2025-55315 | HTTP request smuggling in the ASP.NET Core Kestrel server lets an authenticated attacker bypass security features | 9.9 (Microsoft) | 8.0.21, 9.0.10, 10.0.0; Kestrel.Core 2.3 package | 6.0 and 7.0 not assessed |
| CVE-2026-47304 | EncryptedXml in System.Security.Cryptography.Xml fails to verify signatures properly, exposing encrypted data | 9.8 (NVD) | 8.0.29, 9.0.18, 10.0.10 | 6.0 and 7.0 not assessed |
| CVE-2026-40372 | ASP.NET Core Data Protection 10.0.0 to 10.0.6 lets attackers forge authentication cookies and decrypt some payloads | 9.1 (Microsoft) | 10.0.7 | Only 10.0 is affected |
| CVE-2026-47303 | Improper parsing in the ASP.NET Core Negotiate authentication handler allows elevation of privilege | 8.8 (Microsoft) | 8.0.29, 9.0.18, 10.0.10 | 6.0 and 7.0 not assessed |
| CVE-2026-47300 | Negotiate authentication with LDAP role lookup validates incorrectly, allowing elevation of privilege | 8.8 (Microsoft) | 8.0.29, 9.0.18, 10.0.10 | 6.0 and 7.0 not assessed |
| CVE-2026-50528 | SslStream can be made to skip authorization checks on TLS connections | 8.2 (Microsoft) | 8.0.29, 9.0.18, 10.0.10 | 6.0 and 7.0 not assessed |
| CVE-2026-62898 | Use after free in Microsoft QUIC on Windows discloses memory to an unauthenticated client | 7.5 (Microsoft) | 8.0.30, 9.0.19, 10.0.11 | 6.0 and 7.0 not assessed |
| CVE-2026-45591 | Deeply nested MessagePack arrays overflow the stack in SignalR and Blazor Server | 7.5 (Microsoft) | 8.0.28, 9.0.17, 10.0.9 | 6.0 and 7.0 not assessed |
| CVE-2024-0057 | X.509 chain building returns the wrong failure reason for certificates with malformed signatures, which apps can mistake for success | 9.8 (NVD) | 8.0.1, 7.0.15, 6.0.26 | None of the lines in this guide |
| CVE-2023-44487 | HTTP/2 Rapid Reset floods Kestrel with request cancellations | 7.5 (NVD) | 7.0.12, 6.0.23, and 8.0 before its release | None of the lines in this guide |
| CVE-2023-38180 | Kestrel sometimes fails to disconnect a client it has flagged as malicious | 7.5 (Microsoft) | 7.0.10, 6.0.21 | None of the lines in this guide |
The last three rows show the pattern for an end-of-life .NET line: CVEs Microsoft listed for .NET 6 and 7 while they were supported have fixes in their final releases, and nothing published since has one. The 2026 list is weighted toward ASP.NET Core and TLS: Kestrel request handling, Negotiate authentication, Data Protection, SslStream and EncryptedXml. For an internet-facing ASP.NET Core application on .NET 6 or 7, CVE-2025-55315 is the one to look at first, and Microsoft's advisory lists no mitigating factors for it.
What each line gets
.NET 10
10.0.12 has every fix above that applies to it. If an application ran on 10.0.0 to 10.0.6 with Data Protection, upgrading is not enough for CVE-2026-40372: Microsoft says tokens issued with forged payloads stay valid after the upgrade unless the Data Protection key ring is rotated.
.NET 8 and .NET 9
8.0.31 and 9.0.20 have every 2026 fix that lists them. Both lines leave support on 10 November 2026, so .NET 9 does not buy time over .NET 8. The move to .NET 10 changes the target framework and SDK, and brings the breaking changes in .NET 9 and 10 at once. See .NET 8 end of life, .NET 9 end of life and the .NET 8 to .NET 10 upgrade guide.
.NET 7
7.0.20, from 28 May 2024, is the last release, and it includes the fixes for CVE-2024-0057, CVE-2023-44487 and CVE-2023-38180. It has nothing for the 65 CVEs fixed in .NET 8 since then, including CVE-2025-55315 and the 2026 ASP.NET Core authentication flaws. See .NET 7 end of life.
.NET 6
6.0.35, from 8 October 2024, carried the last .NET 6 security fixes, for CVE-2024-43483, CVE-2024-43484 and CVE-2024-43485, and 6.0.36 in November 2024 was the final release. Many applications stayed on .NET 6 because it was LTS, and they now have no upstream fix for any of the 55 CVEs fixed in .NET 8 since. See .NET 6 end of life.
What to do on each line
- .NET 10. Stay on the latest patch release, and rotate the Data Protection key ring if you ran 10.0.0 to 10.0.6.
- .NET 8 and 9. Move to 8.0.31 or 9.0.20 now and plan the move to .NET 10 before 10 November 2026, or arrange patched builds for after that date.
- .NET 6 and 7. Upgrade to .NET 10, or take patched builds. Until then, put Kestrel behind a reverse proxy or web application firewall that normalises HTTP requests, turn off HTTP/2 and HTTP/3 on endpoints that do not need them, and review where you use Negotiate authentication with LDAP roles, SignalR with MessagePack, or EncryptedXml.
Where OSSeva fits
OSSeva ships patched .NET 6 and .NET 7 runtimes, including ASP.NET Core, and covers .NET 8 and .NET 9 after Microsoft's 10 November 2026 date. OSSeva backports fixes of this class to the end-of-life release lines it patches, and delivers them as signed Docker images, apt and yum packages and binaries. They are available now on the Patch, Assure and Operate tiers. Assure adds NuGet dependency vulnerability scanning, an ASP.NET Core TLS and authentication configuration review and a compliance attestation package, and Operate adds 24/7 CLR and application health monitoring with a 15-minute P1 response and a named senior .NET engineer. See .NET extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.