.NET Framework 4.x — End of Life
Active High risk12 releases in this series34 CVEs
.NET Framework 4.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 4.8.1 | Aug 9, 2022 | — | No | — | Active | |
| 4.8 | Apr 18, 2019 | — | No | — | Active | |
| 4.7.2 | Apr 30, 2018 | — | No | — | Active | |
| 4.7.1 | Oct 17, 2017 | — | No | — | Active | |
| 4.7 | Apr 5, 2017 | — | No | — | Active | |
| 4.6.2 | Aug 2, 2016 | — | Jan 12, 2027 | — | Active | |
| 4.6.1 | Nov 30, 2015 | — | Apr 26, 2022 | — | EOL | |
| 4.6 | Jul 20, 2015 | — | Apr 26, 2022 | — | EOL | |
| 4.5.2 | May 5, 2014 | — | Apr 26, 2022 | — | EOL | |
| 4.5.1 | Oct 17, 2013 | — | Jan 12, 2016 | — | EOL | |
| 4.5 | Aug 15, 2012 | — | Jan 12, 2016 | — | EOL | |
| 4.0 | Apr 12, 2010 | — | Jan 12, 2016 | — | EOL |
CVEs affecting .NET Framework 4.x (34)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-35433 | HIGH | 7.3 | 0.66% | — | 4.7 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-35433 | HIGH | 7.3 | 0.66% | — | 4.8 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-35433 | HIGH | 7.3 | 0.66% | — | 4.7.2 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-35433 | HIGH | 7.3 | 0.66% | — | 4.8.1 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-35433 | HIGH | 7.3 | 0.66% | — | 4.7.1 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.6 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.8.1 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.8 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.6.2 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.7 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.6.1 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.7.2 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-32177 | HIGH | 7.3 | 0.55% | — | 4.7.1 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.7.1 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.6.1 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.6.2 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.7 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.7.2 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.8 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.8.1 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-33116 | HIGH | 7.5 | 2.14% | — | 4.6 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att… | Apr 14, 2026 |
| CVE-2026-32226 | MEDIUM | 5.9 | 0.54% | — | 4.7.1 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an … | Apr 14, 2026 |
| CVE-2026-32226 | MEDIUM | 5.9 | 0.54% | — | 4.7.2 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an … | Apr 14, 2026 |
| CVE-2026-32226 | MEDIUM | 5.9 | 0.54% | — | 4.7 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an … | Apr 14, 2026 |
| CVE-2026-32226 | MEDIUM | 5.9 | 0.54% | — | 4.8.1 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an … | Apr 14, 2026 |
| CVE-2026-32226 | MEDIUM | 5.9 | 0.54% | — | 4.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an … | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.8 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.6.2 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.7.1 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.7 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.6.1 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.6 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.8.1 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
| CVE-2026-23666 | HIGH | 7.5 | 1.33% | — | 4.7.2 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 |
Frequently asked questions
Is .NET Framework 4 end of life?
Partially. Some .NET Framework 4.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect .NET Framework 4?
There are 34 CVEs tracked for .NET Framework 4.x. See the full list above with CVSS and EPSS scores.
What is the latest .NET Framework 4 version?
Check the version table above for the latest .NET Framework 4.x patch release.
When was .NET Framework 4 first released?
.NET Framework 4.0 was initially released on August 9, 2022. See the full version timeline in the table above.
Is it safe to run .NET Framework 4 in production?
.NET Framework 4 is still supported and safe for production use. Ensure you are running the latest patch version to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
