CVE-2026-62900
Analyzed Analyzed - Analysis Complete

Improper Information Disclosure in .NET Framework

Vulnerability report for CVE-2026-62900, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-14

Assigner: Microsoft Corporation

Description

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-14
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
microsoft visual_studio_2022 From 17.14.0 (inc) to 17.14.38 (exc)
microsoft visual_studio_2026 From 18.8.0 (inc) to 18.8.3 (exc)
microsoft .net From 8.0.0 (inc) to 8.0.30 (exc)
microsoft .net From 9.0.0 (inc) to 9.0.19 (exc)
microsoft .net From 10.0.0 (inc) to 10.0.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper removal of sensitive information before storage or transfer in .NET. An unauthorized attacker could exploit this to disclose information over a network.

Detection Guidance

This vulnerability involves improper removal of sensitive information in .NET before storage or transfer. Detection requires reviewing .NET applications for potential exposure of sensitive data in memory, logs, or network transfers. Check for unencrypted sensitive fields in application outputs or network traffic. Use tools like Wireshark to inspect network packets for exposed data. Review application logs for sensitive information leaks.

Impact Analysis

An attacker could access sensitive data transmitted or stored by .NET applications, leading to potential data breaches or unauthorized information disclosure.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations due to unauthorized data exposure, potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Apply the latest security updates from Microsoft for .NET to address the improper information removal issue. Monitor Microsoft's update guide for patches and verify their installation on affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62900. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart