CVE-2026-32178
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- EPSS probability
- 2.28%
- CWE
- CWE-138
- Published
- 2026-04-14
- Last modified
- 2026-08-14
Affected products
- Microsoft .NET 10.0
- Microsoft .NET 8.0
- Microsoft .NET 8.0
- Microsoft .NET 9.0
- Microsoft Microsoft Visual Studio 2022 version 17.12
- Microsoft Microsoft Visual Studio 2022 version 17.14
Weakness type
Related vulnerabilities
- CVE-2026-55841 — Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message
- CVE-2026-26129 — M365 Copilot Information Disclosure Vulnerability
- CVE-2026-20009 — Cisco Secure Firewall Adaptive Security Appliance SSH Partial Private Key Authentication Bypass Vulnerability
- CVE-2025-48939 — tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript
- CVE-2025-5878 — ESAPI esapi-java-legacy SQL Injection Defense Encoder.encodeForSQL special element
- CVE-2024-51500 — Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware
- CVE-2024-38133 — Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-42117 — Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability