CVE-2026-21218Disclosure(apple / .net)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple .net systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-166

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • .net
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-10); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
.netlinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-10: 4Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-10: 2Technical Details · 2026-02-12: 102-1002-1102-12
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-104
Disclosure2Patch2
2026-02-111
Disclosure1
2026-02-121
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-21218 Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-21218

    Post summary

    The post references CVE-2026-21218 as a .NET vulnerability enabling spoofing, but offers no PoC, exploit code, patch, or evidence of active use.

    00010190
    56.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 #Ubuntu .NET CRITICAL 🚨 CVE-2026-21218 lets attackers bypass crypto checks in http://System.Security.Cryptography.Cose. Affects: .NET 8/9/10 on Ubuntu 25.10 & 22.04 LTS. Read more: 👉 https://tinyurl.com/34ny5waj #Security https://t.co/XDQhopPHOb

    Post summary

    The tweet announces CVE-2026-21218, a critical .NET vulnerability that allows bypassing crypto checks on Ubuntu, affecting .NET 8/9/10. No PoC, exploit, active use, patch, or debunking information is provided.

    0000058
    1.3K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-21218 - Microsoft - .NET 10.0 - https://www.redpacketsecurity.com/cve-alert-cve-2026-21218-microsoft-net-10-0/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-21218 #microsoft #net-10-0

    Post summary

    The post announces CVE-2026-21218 and provides a link to a CVE alert page, but offers no further technical or exploit information.

    0000075
    3.5K followersView on X
  • prod42net@prod42net
    Patch

    February 2026 servicing: .NET gets critical security fixes (CVE-2026-21218) across 8.0/9.0/10.0 with 10.0.3/9.0.13/8.0.24; .NET Framework has no new updates this month. Patch now to shield your apps. — Rahul Bhandari (MSFT), Tara Overfield https://ift.tt/jZ0ulMK

    Post summary

    The announcement focuses on releasing critical security patches for .NET 8.0/9.0/10.0 to address CVE-2026-21218.

    0000048
    2.0K followersView on X
  • prod42net@prod42net
    Patch

    February 2026 servicing updates for .NET and .NET Framework bring security fixes across 10.0, 9.0, and 8.0, including CVE-2026-21218. Updates: 10.0.3, 9.0.13, 8.0.24 for installers, binaries, containers, Linux. No new .NET Framework updates this month. … https://ift.tt/jZ0ulMK

    Post summary

    Microsoft released February 2026 servicing updates for .NET and .NET Framework, including fixes for CVE-2026-21218 across multiple version lines.

    0000030
    2.0K followersView on X
  • VulnersHub@VulnersHub
    Disclosure

    CVE-2026-21218 .NET Spoofing Vulnerability http://dlvr.it/TQtFwp

    Post summary

    A brief announcement of CVE-2026-21218, a .NET spoofing vulnerability, accompanied by a link that may contain additional details.

    0000029
    2 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSlinuxlinux_kernel---
Appmicrosoft.net---
OSmicrosoftwindows---

Explore more