Home

Description

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED Reserved 2026-03-11 | Published 2026-04-14 | Updated 2026-06-01 | Assigner microsoft




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Problem types

CWE-138: Improper Neutralization of Special Elements

Product status

10.0.0 (custom) before 10.0.6
affected

8.0 (custom) before 8.0.26
affected

8.0.0 (custom) before 8.0.26
affected

9.0.0 (custom) before 9.0.15
affected

17.12.0 (custom) before 17.12.19
affected

17.14.0 (custom) before 17.14.30
affected

References

msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32178 (.NET Spoofing Vulnerability) vendor-advisory patch

cve.org (CVE-2026-32178)

nvd.nist.gov (CVE-2026-32178)

Download JSON