Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-50528

.NET SslStream: authorization checks can be bypassed on TLS connections

Technology

.NET

CVSS Score

8.2 / 10.0

Affected Versions

.NET 8, 9 and 10 runtimes before the July 2026 releases

Upstream Fix

8.0.29; 9.0.18; 10.0.10

Published

July 14, 2026

OSSeva Coverage

Fixed upstream

Description

A security feature bypass exists in System.Net.Security when processing TLS/SSL connections: an attacker can exploit the SslStream implementation to bypass authorization checks during secure communication. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running .NET 8, 9 and 10 runtimes before the July 2026 releases, you need this patch. Book a discovery call to get covered.