.net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 vulnerabilities
CVEs whose affected-version data names the .net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-69522High· 8.8Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
▾ TwilightMicrosoft · .NET 10.0EPSS 0.91%via NVD
CVE-2026-62872High· 8.8.NET Framework Elevation of Privilege Vulnerability
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
▾ TwilightMicrosoft · Microsoft .NET Framework 3.5EPSS 0.78%via CVEORG
CVE-2026-65810High· 7.8.NET Framework Elevation of Privilege Vulnerability
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
▾ TwilightMicrosoft · Microsoft .NET Framework 3.5EPSS 0.40%via CVEORG
CVE-2026-70354High· 7.8.NET Core Remote Code Execution Vulnerability
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
▾ TwilightMicrosoft · .NET 10.0EPSS 0.36%via CVEORG