High severity7.5GHSA Advisory· Published Apr 14, 2026· Updated May 6, 2026
CVE-2026-33116
CVE-2026-33116
Description
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
System.Security.Cryptography.XmlNuGet | >= 10.0.0, < 10.0.6 | 10.0.6 |
System.Security.Cryptography.XmlNuGet | >= 9.0.0, < 9.0.15 | 9.0.15 |
System.Security.Cryptography.XmlNuGet | >= 8.0.0, < 8.0.3 | 8.0.3 |
Affected products
9cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-37gx-xxp4-5rgxghsaADVISORY
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33116nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-33116ghsaADVISORY
- github.com/dotnet/announcements/issues/392ghsaWEB
- github.com/dotnet/runtime/security/advisories/GHSA-37gx-xxp4-5rgxghsaWEB
News mentions
49- Living Off the Pipeline: Defending Against CI/CD SubversionSentinelOne Labs · May 15, 2026
- Sweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’SecurityWeek · May 13, 2026
- New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network PivotsThe Hacker News · May 12, 2026
- Build Application Firewalls Aim to Stop the Next Supply Chain AttackSecurityWeek · May 11, 2026
- Linux developers weigh emergency “killswitch” for vulnerable kernel functionsHelp Net Security · May 11, 2026
- Final Countdown: Last Chance to Join the Rapid7 Global Cybersecurity SummitRapid7 Blog · May 11, 2026
- A week in security (May 4 – May 10)Malwarebytes Labs · May 11, 2026
- Why Security in 2026 Requires Continuous Threat and Exposure Management (CTEM) at ScaleRapid7 Blog · May 7, 2026
- How Cloudflare responded to the “Copy Fail” Linux vulnerabilityCloudflare Blog · May 7, 2026
- Open-source MCP server monitoring for Python appsHelp Net Security · May 7, 2026
- Muddying the Tracks: The State-Sponsored Shadow Behind Chaos RansomwareRapid7 Blog · May 6, 2026
- Attackers adopt JavaScript runtime Bun to spread NWHStealerMalwarebytes Labs · May 6, 2026
- ServiceNow clears agents for landing with new AI control towerThe Register Security · May 5, 2026
- A Walkthrough of the 2026 Global Cybersecurity Summit AgendaRapid7 Blog · May 5, 2026
- UAT-8302 and its box full of malwareCisco Talos Intelligence · May 5, 2026
- CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos Intelligence · May 5, 2026
- TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03), (Mon, May 4th)SANS Internet Storm Center · May 4, 2026
- Shadow IT has given way to shadow AI. Enter AI-BOMsThe Register Security · May 4, 2026
- Code Orange: Fail Small is complete. The result is a stronger Cloudflare networkCloudflare Blog · May 1, 2026
- The Good, the Bad and the Ugly in Cybersecurity – Week 18SentinelOne Labs · May 1, 2026
- Introducing Dynamic Workflows: durable execution that follows the tenantCloudflare Blog · May 1, 2026
- Microsoft won’t patch PhantomRPC: Feature or bug?Malwarebytes Labs · Apr 29, 2026
- Mastering agentic AI security through exposure managementTenable Blog · Apr 29, 2026
- 30 ClawHub skills secretly turn AI agents into a crypto swarmThe Register Security · Apr 29, 2026
- VECT: Ransomware by design, Wiper by accidentCheck Point Research · Apr 28, 2026
- TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)SANS Internet Storm Center · Apr 27, 2026
- 3 Reasons to Attend our Global Cybersecurity Summit if you’re Focused on AI, Threats, and CTEMRapid7 Blog · Apr 24, 2026
- AI is Changing Vulnerability Discovery and your Software Supply Chain Strategy has to Change with itRapid7 Blog · Apr 23, 2026
- Making Rust Workers reliable: panic and abort recovery in wasm‑bindgenCloudflare Blog · Apr 22, 2026
- Kyber Ransomware Double Trouble: Windows and ESXi Attacks ExplainedRapid7 Blog · Apr 21, 2026
- Project Glasswing and the Next Challenge for Defenders: Turning Faster Discovery into Faster ActionRapid7 Blog · Apr 20, 2026
- The AI engineering stack we built internally — on the platform we shipCloudflare Blog · Apr 20, 2026
- Orchestrating AI Code Review at scaleCloudflare Blog · Apr 20, 2026
- Metasploit Wrap-Up 04/17/2026Rapid7 Blog · Apr 17, 2026
- Unweight: how we compressed an LLM 22% without sacrificing qualityCloudflare Blog · Apr 17, 2026
- Introducing Flagship: feature flags built for the age of AICloudflare Blog · Apr 17, 2026
- Frontier AI Reinforces the Future of Modern Cyber DefenseSentinelOne Labs · Apr 16, 2026
- Artifacts: versioned storage that speaks GitCloudflare Blog · Apr 16, 2026
- Patch Tuesday - April 2026Rapid7 Blog · Apr 14, 2026
- Your Cloud Detection Strategy in 2026: What to Expect at the Global Cybersecurity SummitRapid7 Blog · Apr 14, 2026
- 6th April – Threat Intelligence ReportCheck Point Research · Apr 6, 2026
- The Good, the Bad and the Ugly in Cybersecurity – Week 14SentinelOne Labs · Apr 3, 2026
- ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution RuntimeCheck Point Research · Mar 30, 2026
- Iranian MOIS Actors & the Cyber Crime ConnectionCheck Point Research · Mar 10, 2026
- Risky Business #826 -- A week of AI mishaps and skulduggeryRisky Business · Feb 25, 2026
- ABB AC500 V3 Multiple VulnerabilitiesCISA Alerts
- Siemens SIMATICCISA Alerts
- ABB B&R Automation RuntimeCISA Alerts
- Siemens SIMATICCISA Alerts