Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-47304

.NET: EncryptedXml signature verification flaw allows security feature bypass

Technology

.NET

CVSS Score

9.8 / 10.0

Affected Versions

System.Security.Cryptography.Xml in .NET 8, 9 and 10 before the July 2026 releases

Upstream Fix

8.0.29; 9.0.18; 10.0.10

Published

July 14, 2026

OSSeva Coverage

Fixed upstream

Description

Improper verification of a cryptographic signature in the XML encryption implementation (EncryptedXml in System.Security.Cryptography.Xml) lets an attacker bypass encryption protections and access encrypted data over a network. NVD scores the record 9.8; Microsoft scores it 8.1.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running System.Security.Cryptography.Xml in .NET 8, 9 and 10 before the July 2026 releases, you need this patch. Book a discovery call to get covered.