🟠 High  |  Source: Microsoft Security Response Center


CVE-2026-50650 is an elevation of privilege vulnerability affecting the .NET Framework, meaning an attacker could potentially gain higher-level permissions than intended on a vulnerable system. Microsoft has issued an update to the Software Update table, described as an informational change with no new technical findings. Organisations running .NET Framework workloads — including those hosted on Azure — should ensure applicable patches are applied.

Security Architect’s Take: Review your Azure and on-premises workloads running .NET Framework and confirm that the relevant security updates have been deployed; use Microsoft Defender for Cloud or your patch management tooling to identify any unpatched instances at scale.

Original advisory: CVE-2026-50650 .NET Framework Elevation of Privilege Vulnerability