🟠 High | Source: Microsoft Security Response Center
CVE-2026-47304 is a security feature bypass vulnerability in Microsoft .NET, which could allow an attacker to circumvent built-in security controls within .NET applications. Microsoft has issued an updated advisory with revised product information in the Software Update table, though the vulnerability details themselves remain unchanged. Organisations running .NET workloads, including those hosted on Azure, should review the updated guidance to ensure the correct patches are applied.
Security Architect’s Take: Review the updated Software Update table in the MSRC advisory to confirm the correct .NET versions are in scope for your environment, then validate that patching pipelines — including Azure App Service, AKS workloads, and any containerised .NET runtimes — are targeting the right package versions.
Original advisory: CVE-2026-47304 .NET Security Feature Bypass Vulnerability