High severity8.8NVD Advisory· Published Aug 11, 2026· Updated Aug 14, 2026
CVE-2026-62872
CVE-2026-62872
Description
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
Affected products
9(expand)+ 7 more
- (no CPE)
- cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62872nvdPatchVendor Advisory
News mentions
3- Microsoft August 2026 Update Breaks When Generating PDF/XPS ContentCyber Security News · Aug 25, 2026
- Patch Tuesday - August 2026Rapid7 Blog · Aug 11, 2026
- Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-DaysCyber Security News · Aug 11, 2026