.NET Framework 4.x — End of Life

Active High risk
12 releases in this series234 CVEs

.NET Framework 4.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
4.8.1Aug 9, 2022NoActive
4.8Apr 18, 2019NoActive
4.7.2Apr 30, 2018NoActive
4.7.1Oct 17, 2017NoActive
4.7Apr 5, 2017NoActive
4.6.2Aug 2, 2016Jan 12, 2027Active
4.6.1Nov 30, 2015Apr 26, 2022EOL
4.6Jul 20, 2015Apr 26, 2022EOL
4.5.2May 5, 2014Apr 26, 2022EOL
4.5.1Oct 17, 2013Jan 12, 2016EOL
4.5Aug 15, 2012Jan 12, 2016EOL
4.0Apr 12, 2010Jan 12, 2016EOL

CVEs affecting .NET Framework 4.x (234)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-70354HIGH7.80.29%4.8Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-70354HIGH7.80.29%4.8.1Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-70354HIGH7.80.29%4.7.1Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-70354HIGH7.80.29%4.6Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-70354HIGH7.80.29%4.7.2Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-70354HIGH7.80.29%4.6.1Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-70354HIGH7.80.29%4.7Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-70354HIGH7.80.29%4.6.2Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.7.2Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.6Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.8.1Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.8Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.6.2Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.7Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.6.1Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-65810HIGH7.80.26%4.7.1Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11, 2026
CVE-2026-62897HIGH7.00.33%4.8.1Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-62897HIGH7.00.33%4.7Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-62897HIGH7.00.33%4.7.1Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-62897HIGH7.00.33%4.8Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-62897HIGH7.00.33%4.7.2Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.8Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.6.2Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.7.1Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.6.1Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.8.1Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.6Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.7.2Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-62872HIGH8.80.53%4.7Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11, 2026
CVE-2026-50659MEDIUM6.50.55%4.8Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50659MEDIUM6.50.55%4.6.2Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50659MEDIUM6.50.55%4.7.1Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50659MEDIUM6.50.55%4.8.1Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50659MEDIUM6.50.55%4.7.2Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50659MEDIUM6.50.55%4.6Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50659MEDIUM6.50.55%4.6.1Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50659MEDIUM6.50.55%4.7Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.6Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.6.2Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.7.2Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.7.1Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.7Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.8.1Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.6.1Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50650HIGH7.80.29%4.8Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p…Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.6.1Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.8Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.7.2Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.8.1Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.6Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.7.1Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.7Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50649HIGH7.80.93%4.6.2Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.8Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.7.1Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.8.1Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.7Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.6.1Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.7.2Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.6.2Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50648HIGH7.50.84%4.6Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o…Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.7.1Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.7.2Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.6.2Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.6.1Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.7Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.8Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.6Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50646HIGH7.80.96%4.8.1Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.6Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.7Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.8.1Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.7.1Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.6.1Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.6.2Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.8Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50527HIGH7.50.84%4.7.2Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.7Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.6Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.8.1Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.8Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.6.2Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.6.1Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.7.2Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50525HIGH7.50.60%4.7.1Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.7.2Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.6.1Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.7Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.7.1Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.8Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.6Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.8.1Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47304HIGH8.10.21%4.6.2Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.8.1Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.6.2Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.7.2Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.6Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.6.1Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.8Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.7.1Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-47302HIGH7.51.02%4.7Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.6.2Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.7.2Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.7Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.6.1Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.8Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.7.1Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.8.1Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50647HIGH7.51.17%4.6Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.6.2Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.7Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.7.2Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.7.1Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.8.1Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.6Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.8Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50411HIGH7.51.17%4.6.1Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.6.1Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.8Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.7.1Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.7Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.6Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.7.2Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.6.2Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50368HIGH7.51.17%4.8.1Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.7.2Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.6.1Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.6.2Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.8Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.7.1Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.7Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.8.1Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50355HIGH7.51.17%4.6Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.8.1Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.8Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.6.2Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.7.1Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.6Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.7Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.7.2Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50653HIGH7.51.17%4.6.1Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.7.1Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.8Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.6.2Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.6.1Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.8.1Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.6Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.7Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-50652HIGH7.51.73%4.7.2Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo…Jul 14, 2026
CVE-2026-35433HIGH7.30.66%4.8.1Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-35433HIGH7.30.66%4.7Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-35433HIGH7.30.66%4.7.1Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-35433HIGH7.30.66%4.7.2Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-35433HIGH7.30.66%4.8Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.6Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.7.2Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.7Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.8.1Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.7.1Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.6.1Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.6.2Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-32177HIGH7.30.55%4.8Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.May 12, 2026
CVE-2026-33116HIGH7.52.14%4.6.2Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-33116HIGH7.52.14%4.6.1Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-33116HIGH7.52.14%4.8Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-33116HIGH7.52.14%4.8.1Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-33116HIGH7.52.14%4.7.2Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-33116HIGH7.52.14%4.7.1Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-33116HIGH7.52.14%4.7Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-33116HIGH7.52.14%4.6Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att…Apr 14, 2026
CVE-2026-32226MEDIUM5.90.54%4.8Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an …Apr 14, 2026
CVE-2026-32226MEDIUM5.90.54%4.7.2Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an …Apr 14, 2026
CVE-2026-32226MEDIUM5.90.54%4.7Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an …Apr 14, 2026
CVE-2026-32226MEDIUM5.90.54%4.8.1Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an …Apr 14, 2026
CVE-2026-32226MEDIUM5.90.54%4.7.1Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an …Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.7.2Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.6.2Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.7Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.8.1Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.6.1Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.6Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.7.1Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2026-23666HIGH7.51.33%4.8Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.Apr 14, 2026
CVE-2023-36899HIGH8.876.71%4.8.1ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36899HIGH8.876.71%4.6ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36899HIGH8.876.71%4.8ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36899HIGH8.876.71%4.7.1ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36899HIGH8.876.71%4.6.2ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36899HIGH8.876.71%4.7.2ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36899HIGH8.876.71%4.6.1ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36899HIGH8.876.71%4.7ASP.NET Elevation of Privilege VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.6.2.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.8.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.6.1.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.7.1.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.7.2.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.6.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.7.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-36873HIGH7.41.50%4.8.1.NET Framework Spoofing VulnerabilityAug 8, 2023
CVE-2023-21808HIGH7.81.14%4.7.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21808HIGH7.81.14%4.8.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21808HIGH7.81.14%4.8.1.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21808HIGH7.81.14%4.7.1.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21808HIGH7.81.14%4.6.2.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21808HIGH7.81.14%4.6.1.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21808HIGH7.81.14%4.7.2.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21808HIGH7.81.14%4.6.NET and Visual Studio Remote Code Execution VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.8.1.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.6.1.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.7.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.8.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.7.2.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.6.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.7.1.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2023-21722MEDIUM5.00.91%4.6.2.NET Framework Denial of Service VulnerabilityFeb 14, 2023
CVE-2022-41064MEDIUM5.80.76%4.8.1.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2022-41064MEDIUM5.80.76%4.6.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2022-41064MEDIUM5.80.76%4.6.1.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2022-41064MEDIUM5.80.76%4.6.2.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2022-41064MEDIUM5.80.76%4.7.1.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2022-41064MEDIUM5.80.76%4.7.2.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2022-41064MEDIUM5.80.76%4.7.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2022-41064MEDIUM5.80.76%4.8.NET Framework Information Disclosure VulnerabilityNov 9, 2022
CVE-2020-1108HIGH7.56.25%4.7.2A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.6.1A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.7.1A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.7A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.8.1A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.5A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.5.2A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.8A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.6.2A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.6A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020
CVE-2020-1108HIGH7.56.25%4.5.1A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker w…May 21, 2020

Frequently asked questions

Is .NET Framework 4 end of life?

Partially. Some .NET Framework 4.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect .NET Framework 4?

There are 234 CVEs tracked for .NET Framework 4.x. See the full list above with CVSS and EPSS scores.

What is the latest .NET Framework 4 version?

Check the version table above for the latest .NET Framework 4.x patch release.

When was .NET Framework 4 first released?

.NET Framework 4.0 was initially released on August 9, 2022. See the full version timeline in the table above.

Is it safe to run .NET Framework 4 in production?

.NET Framework 4 is still supported and safe for production use. Ensure you are running the latest patch version to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA