CVE-2026-26127Patch(apple / .net)

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch apple .net systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • .net
  • bcl.memory
  • linux_kernel
  • macos

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 56 mentions across 22 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 39 signals
  • Technical details provided in 28 signals
  • Disclosure: 12 classified signals
  • General: 6 classified signals
  • Peaked 20d ago at 9 mentions (2026-03-11); latest day: 1
  • 56 total mentions across 22 days

Affected systems

Products
.netbcl.memorylinux_kernelmacoswindows

1 version affected across 5 products

Deep dive

Activity timeline56 mentions / 22d
02579Mentions · 2026-03-10: 5Mentions · 2026-03-11: 9Mentions · 2026-03-12: 8Mentions · 2026-03-13: 4Mentions · 2026-03-14: 1Mentions · 2026-03-16: 3Mentions · 2026-03-17: 2Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-20: 3Mentions · 2026-03-21: 1Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Mentions · 2026-03-29: 2Mentions · 2026-04-14: 1Mentions · 2026-05-11: 4Mentions · 2026-05-12: 2Mentions · 2026-05-13: 2Mentions · 2026-05-17: 1Mentions · 2026-05-24: 1Mentions · 2026-05-27: 1Mentions · 2026-06-23: 1PoC Mentioned / Linked · 2026-03-10: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-12: 1Patch / Workaround · 2026-03-10: 4Patch / Workaround · 2026-03-11: 7Patch / Workaround · 2026-03-12: 7Patch / Workaround · 2026-03-13: 3Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-17: 2Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-05-11: 3Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-03-10: 4Technical Details · 2026-03-11: 8Technical Details · 2026-03-12: 5Technical Details · 2026-03-14: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 1Technical Details · 2026-03-29: 2Technical Details · 2026-04-14: 1Technical Details · 2026-05-11: 103-1003-1203-1403-1703-1903-2103-2704-1405-1205-1705-2706-23
Signal classification5 categories
Patch
3664.3%
Disclosure
1221.4%
General
610.7%
PoC
11.8%
Active Exploitation
11.8%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-105
Patch4PoC1
2026-03-119
Active Exploitation1Disclosure1General1Patch6
2026-03-128
Disclosure2Patch6
2026-03-134
General1Patch3
2026-03-141
Disclosure1
2026-03-163
Disclosure1Patch2
2026-03-172
Disclosure1Patch1
2026-03-181
Disclosure1
2026-03-191
Patch1
2026-03-203
General1Patch2
2026-03-211
General1
2026-03-262
Patch2
2026-03-271
Patch1
2026-03-292
Disclosure1Patch1
2026-04-141
Patch1
2026-05-114
Disclosure1Patch3
2026-05-122
Disclosure1General1
2026-05-132
Disclosure1Patch1
2026-05-171
Disclosure1
2026-05-241
Patch1
2026-05-271
General1
2026-06-231
Patch1
Full discourse20 posts
  • SoyITPro@SoyITPro
    Patch

    🔒 Updates – Marzo 2026 Microsoft corrige 84 fallos, incluyendo 8 críticos en Windows, Office, SQL Server, .NET y Azure: 🛑 CVE-2026-26127 (.NET) – Denegación de servicio por lectura fuera de límites. 📊 CVE-2026-21262 (SQL Server) – Escalada de privilegios hasta SQLAdmin. 📄 CVE-2026-26113 (Office) – RCE por puntero no confiable (CVSS 8.4) 📄 CVE-2026-26110 (Office) – RCE por confusión de tipos, explotable vía Panel de Vista Previa. 📊 CVE-2026-26144 (Excel) – Divulgación de información sensible en generación web. 🌐 CVE-2026-23654 (GitHub/PyPI) – RCE por dependencia maliciosa en paquetes de terceros. #Security #Windows #Updates

    Post summary

    Microsoft announced patches for 84 vulnerabilities, including critical RCEs in Office/.NET, privilege escalation in SQL Server, and a denial‑of‑service flaw in .NET.

    0703131.3K
    12.3K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🛡️ MS ACI Containers crits: CVE-2026-23651/26124 (6.7 EoP). No wild exploits yet, but enterprise cloud alert! https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    The post highlights that CVE‑2026‑23651/26124—affecting Microsoft ACI Containers with a 6.7 EoP—has no active exploitation yet and directs readers to a Tenable blog outlining the March 2026 Patch Tuesday update.

    0003074
    438 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年3月ぱっちちゅーずーでー ▼Microsoft 2026 年 3 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/03/202603-security-update CVE-2026-26127 .NET のサービス拒否の脆弱性 CVE-2026-21262 SQL サーバーの特権の昇格の脆弱性 ▼SAP SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html CVE-2019-17571 SAP Quotation Management Insurance アプリケーション (FS-QUO) におけるコードインジェクションの脆弱性 CVE-2026-27685 SAP NetWeaver Enterprise Portal 管理における安全でないデシリアライゼーション ▼Ivanti(critical系はなし) March 2026 Security Update https://www.ivanti.com/blog/march-2026-security-update CVE-2026-3483 バージョン 2026.1.1 より前の Ivanti DSM で公開されている危険な方法により、ローカルで認証された攻撃者が権限を昇格できる可能性 ▼Fortinet(critical系はなし) https://fortiguard.fortinet.com/psirt CVE-2026-22627 LLDP OUIフィールドのバッファオーバーフロー CVE-2025-54820 fgtupdates サービスによるバッファオーバーフロー ▼Adobe https://helpx.adobe.com/security.html

    Post summary

    The post lists multiple vendor security updates for March 2026, including CVE identifiers and brief vulnerability types, indicating that patches are available.

    100201.1K
    11.4K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    MS定例更新のTenable社解説。83件。緊急(Critical)が8件で75件が重要。 https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    Tenable’s blog entry lists Microsoft’s March‑2026 Patch Tuesday, covering 83 CVEs—8 Critical and 75 Important—without mentioning exploitation or PoCs, but noting the release of patches.

    00012599
    7.3K followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    💳 CVE-2026-26125 (MS Payment Orchestrator): 8.6 EoP missing auth for critical func. No interaction needed. https://nvd.nist.gov/vuln/detail/CVE-2026-26127 *(Note: Related to Patch Tuesday)

    Post summary

    The note announces CVE-2026-26125, an 8.6 privilege‑elevation vulnerability in the MS Payment Orchestrator that requires no interaction, and links to the NVD page, but provides no evidence of exploitation, PoC, or patch information.

    1001059
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🗄️ SQL Server priv-esc (CVE-2026-21262) Network-local EoP to DB admin (CVSS 8.8, publicly known). Exposed SQL = owned DB. Firewall + patch. https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127 #SQL #CVE

    Post summary

    The post reports CVE-2026-21262, a SQL Server privilege escalation vulnerability with CVSS 8.8, and confirms it has been addressed by Microsoft’s March 2026 Patch Tuesday, recommending firewall and patch as mitigations.

    1001068
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🚨 Adobe Illustrator APSB26-18: Critical untrusted search path (CVSS 8.6) → DLL hijacking via .ai files + heap/stack overflows. Patch now! https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    The tweet highlights a critical Adobe Illustrator vulnerability involving DLL hijacking and memory overflows, and urges users to apply the available patch.

    1001046
    350 followersView on X
  • Duende Software@DuendeIdentity
    Patch

    We’ve shipped patch releases across our library stack to address transitive NuGet vulnerability warnings related to CVE-2026-26127 in Microsoft.BCL.Memory. More details: https://duende.link/nx6127 #dotnet

    Post summary

    Patch releases have been distributed to mitigate CVE-2026-26127 in Microsoft.BCL.Memory; no exploit or active exploitation details are disclosed.

    01010172
    1.8K followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Disclosure

    🎙️ RadioCSIRT Ép.595 – Épisode Spécial du jeudi 12 mars 2026 Un seul sujet. Un cycle qui marque l'histoire des CVE : le Patch Tuesday Microsoft de mars 2026. 🔴 Microsoft Patch Tuesday – 79 vulnérabilités corrigées, deux zero-days publiquement divulgués. CVE-2026-26113 et CVE-2026-26110 : deux RCE critiques dans Microsoft Office déclenchables par simple visualisation d'un message dans le volet de prévisualisation, sans interaction utilisateur. 🔴 CVE-2026-26144 – Microsoft Excel et Copilot Agent Mode. Divulgation d'informations critique : un attaquant peut forcer Copilot à exfiltrer des données via un trafic réseau non prévu. Attaque zero-click documentée. 🔴 CVE-2026-21262 – SQL Server, élévation de privilèges jusqu'au niveau sysadmin via le réseau (CVSS 8.8). Zero-day publiquement divulgué avant correctif. CVE-2026-26127 – .NET, déni de service réseau sans authentification. 🔴 Six vulnérabilités Important signalées comme prioritaires par Cisco Talos et Tenable : Windows Graphics Component, Windows Kernel, Windows Accessibility Infrastructure, Windows SMB Server, Ancillary Function Driver for WinSock, Winlogon (découverte par Google Project Zero). 🔴 CVE-2026-21536 – CVSS 9.8 Critical. Première CVE officiellement attribuée à un agent IA autonome : XBOW, agent de penetration testing entièrement automatisé, sans accès au code source. Microsoft a corrigé côté serveur, sans action requise des utilisateurs. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-595-episode-special-patch-tuesday-microsoft-mars-2026/ 📖 Analyse complète sur le blog : https://blog.marcfredericgomez.fr/microsoft-patch-tuesday-mars-2026-79-vulnerabilites-corrigees-deux-zero-days-divulgues/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #PatchTuesday #Microsoft #CVE #ZeroDay #RCE #Windows #Office #SQLServer #Copilot #AI #XBOW #PatchManagement #VulnerabilityManagement #InfoSec #CERT #CSIRT #SOC #CISO #VOC #Patch

    Post summary

    The post outlines Microsoft Patch Tuesday 2026, listing numerous CVEs with technical details and noting that patches are available and no action is required. It serves as a disclosure of vulnerabilities and their remediation.

    0002060
    413 followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Patch

    🛡️ Manual Técnico: #Vulnerabilidad CVE-2026-26127 en el #Runtime de .NET (+ACTUALIZACIÓN) https://www.newstecnicas.com/2026/05/cve-2026-26127-dotnet-runtime-vulnerabilidad-seguridad.html

    Post summary

    The post announces CVE‑2026‑26127 in the .NET Runtime and refers to an update that likely includes patch information.

    0100041
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Disclosure

    🛡️ Manual Técnico: Vulnerabilidad CVE-2026-26127 en el Runtime de .NET (+ACTUALIZACIÓN) https://www.newstecnicas.com/2026/05/cve-2026-26127-dotnet-runtime-vulnerabilidad-seguridad.html

    Post summary

    The tweet announces a new .NET Runtime vulnerability (CVE‑2026‑26127) and links to a detailed article, but offers no additional technical information, PoC, exploitation evidence, or patch details.

    0100042
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    General

    🛡️ Manual Técnico: #Vulnerabilidad CVE-2026-26127 en el #Runtime de .NET (+ACTUALIZACIÓN) https://www.newstecnicas.com/2026/05/cve-2026-26127-dotnet-runtime-vulnerabilidad-seguridad.html

    Post summary

    The tweet announces a CVE-2026-26127 vulnerability affecting the .NET runtime and hints at an upcoming update, but provides no technical or exploit details.

    0100043
    1.2K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    📊 CVE-2026-21262 (Microsoft SQL Server): 8.8 EoP to sysadmin publicly disclosed. Patch: March 2026 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21262 https://nvd.nist.gov/vuln/detail/CVE-2026-21262 https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    The post describes a CVE-2026-21262 vulnerability in Microsoft SQL Server with a high‑severity (CVSS 8.8) privilege‑escalation flaw, and announces that Microsoft released a patch in March 2026.

    1000052
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🔓 CVE-2026-26127 (SmartScreen Bypass): Microsoft flaw lets malicious files evade detection. Social engineering vector. Patch your Windows! https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26127

    Post summary

    Microsoft released a patch for CVE-2026-26127, which enables malicious files to bypass SmartScreen; users are urged to update their systems.

    1000041
    492 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft .NET のゼロデイ DoS 脆弱性 CVE-2026-26127 が FIX:境界外読み込みによるクラッシュ https://iototsecnews.jp/2026/03/11/microsoft-net-0-day-vulnerability-enables-denial-of-service-attacks/ Microsoft は2026年3月10日に、.NET に存在する深刻なゼロデイ脆弱性 CVE-2026-26127 (CVSS:7.5) を公開しました。この問題の原因は、メモリ処理における境界外読み取り (CWE-125) にあります。この脆弱性を悪用する未認証のリモート攻撃者は、ネットワーク経由で細工したリクエストを送信するだけで、アプリケーションを強制終了させ、サービス停止 (DoS) 状態に追い込めます。攻撃において、特別な権限やユーザーの操作は必要とされません。WindowsだけでなくmacOS/Linux 上の.NET環境や、特定のメモリ関連パッケージ (Microsoft.Bcl.Memory) も影響を受けるため、広範囲なシステムで可用性が損なわれるリスクがあります。ご利用のチームは、ご注意ください。 #dotNET #CVE202626127 #Microsoft #Vulnerability #ZeroDay

    Post summary

    Microsoft disclosed a zero‑day DoS vulnerability in .NET (CVE‑2026‑26127) that permits unauthenticated remote attackers to crash applications via an out‑of‑bounds read; no PoC, exploit, or patch details were mentioned.

    01000179
    484 followersView on X
  • Peter Casano@pcasano
    Patch

    #Microsoft’s March 2026 Patch Tuesday Addresses 83 CVEs (CVE-2026-21262, CVE-2026-26127) http://ow.ly/j8o8106vUOo https://t.co/pMVRJ5DMAX

    Post summary

    The tweet announces Microsoft's March 2026 Patch Tuesday, which addresses 83 CVEs—including CVE-2026-21262 and CVE-2026-26127—and links to further details.

    0001041
    15 followersView on X
  • Dirk Althaus@dirkalthausinv
    General

    4/ Während CVE-2026-21262 und CVE-2026-26127 die unmittelbare Gefahr darstellen, zeigt sich im Hintergrund ein besorgniserregender Trend: Künstliche Intelligenz revolutioniert die Art und Weise, wie Schwachstellen entdeckt und ausgenutzt werden – sowohl von Angreifer...

    Post summary

    The passage merely notes that CVE‑2026‑21262 and CVE‑2026‑26127 pose immediate threats, without providing any additional technical or operational details.

    1000044
    85 followersView on X
  • Cyber News Live@cybernewslive
    Patch

    Microsoft has released its monthly security update fixing 79 flaws, including a bug in SQL Server (CVE-2026-21262) that lets someone with basic access quietly promote themselves to full database administrator, and a flaw http://in.NET (CVE-2026-26127) that lets attackers crash apps remotely. If you use Windows, open Settings, click Windows Update, then Check for updates — your computer will download and install the fixes automatically. Restart when prompted to finish the update. 💥 #CyberNewsLive https://malwarebytes.com/blog/news/2026/03/march-2026-patch-tuesday-fixes-two-zero-day-vulnerabilities

    Post summary

    Microsoft issued a patch covering CVE‑2026‑21262 and CVE‑2026‑26127; the post details how to apply the update and briefly explains the vulnerabilities but offers no exploit or PoC information.

    0001071
    1.6K followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft ■ 新規セキュリティ アドバイザリの公開 なし ■ 既存のセキュリティ アドバイザリの更新 なし ■ 脆弱性の詳細が一般へ公開されていることを確認済み:2 件 ・CVE-2026-21262 SQL サーバーの特権の昇格の脆弱性 ・CVE-2026-26127 .NET のサービス拒否の脆弱性

    Post summary

    The tweet confirms that details for CVE-2026-21262 and CVE-2026-26127 have been publicly released, but provides no PoC, exploit, patch information, or evidence of active exploitation.

    10000104
    89 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Microsoft patched 83 vulnerabilities, including a critical RCE (CVE-2026-21536) fully mitigated. Two bugs disclosed: .NET DoS (CVE-2026-26127) and SQL Server privilege escalation (CVE-2026-21262). #MicrosoftUpdate #AzureSecurity #USA https://ift.tt/Rwdi9f7

    Post summary

    The tweet announces that Microsoft has patched 83 vulnerabilities, including a critical remote code execution flaw, a .NET denial‑of‑service bug, and a SQL Server privilege escalation issue, with all fixes now applied.

    00010166
    3.7K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSlinuxlinux_kernel---
Appmicrosoft.net---
Appmicrosoftbcl.memory---
OSmicrosoftwindows---

Explore more