Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-62898

.NET: use after free in Microsoft QUIC discloses memory

Technology

.NET

CVSS Score

7.5 / 10.0

Affected Versions

.NET 8, 9 and 10 runtimes on Windows before the August 2026 releases

Upstream Fix

8.0.30; 9.0.19; 10.0.11

Published

August 11, 2026

OSSeva Coverage

Fixed upstream

Description

A use after free in Microsoft QUIC, as shipped with the .NET runtime on Windows, lets an unauthenticated attacker disclose information over a network. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running .NET 8, 9 and 10 runtimes on Windows before the August 2026 releases, you need this patch. Book a discovery call to get covered.