Summary
A race condition in Microsoft .NET Framework lets an unauthenticated remote attacker trigger a denial of service in affected applications. By sending crafted network traffic that hits the vulnerable concurrent-execution code path, the attacker can crash or hang the service. The result is service unavailability rather than code execution or data theft.
Why Planned Fix?
3/6Exploitation Details
Crash or hang the affected application or service, making it unavailable.
Denial of ServiceAffected Software
| Product | Affected Versions |
|---|---|
| Microsoft .NET Framework | 3.0, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1 |
Microsoft .NET Framework is a Windows application runtime and class library platform used to build and run managed desktop, server, and web applications.
Affected ComponentCore runtime concurrency and exception-handling logic used by .NET Framework applications.
Core runtime concurrency and exception-handling logic used by .NET Framework applications.
Not available
Not available
Apply the April 14, 2026 .NET Framework cumulative update for your Windows release; Microsoft shipped the fix through the monthly servicing updates for supported .NET Framework versions.
Apply the April 14, 2026 .NET Framework cumulative update for your Windows release; Microsoft shipped the fix through the monthly servicing updates for supported .NET Framework versions.
Probability of exploitation in the next 30 days
Worse than 25% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Sources
| Source | Article |
|---|---|
| learn.microsoft.com | April 2026 cumulative update - .NET Framework |
| devblogs.microsoft.com | .NET and .NET Framework April 2026 servicing releases updates |
| msrc.microsoft.com | CVE-2026-23666 update guide |
| tenable.com | CVE-2026-23666 |
| blog.qualys.com | Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review |
| crowdstrike.com | April 2026 Patch Tuesday: Updates and Analysis |
Priority History
Initial analysis