Summary

Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability

Advisory details

Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A spoofing vulnerability exists in the SMTP client implementation (System.Net.Mail) in .NET 8, .NET 9, and .NET 10, where an attacker can spoof messages during message routing.

Announcement

Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/**TBD**

CVSS Details

  • Version: 3.1
  • Severity: Medium
  • Score: 6.5
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • Weakness: CWE-116 (Improper Encoding or Escaping of Output)

Affected Platforms

  • Platforms: All
  • Architectures: All

Affected Packages

The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below

.NET 10.0

Package name Affected version Patched version
Microsoft.NetCore.App.Runtime.linux-arm >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.linux-arm64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.linux-musl-arm >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.linux-musl-arm64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.linux-musl-x64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.linux-x64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.osx-arm64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.osx-x64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.win-arm >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.win-arm64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.win-x64 >= 10.0.0, <= 10.0.9 10.0.10
Microsoft.NetCore.App.Runtime.win-x86 >= 10.0.0, <= 10.0.9 10.0.10

.NET 9.0

Package name Affected version Patched version
Microsoft.NetCore.App.Runtime.linux-arm >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.linux-arm64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.linux-musl-arm >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.linux-musl-arm64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.linux-musl-x64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.linux-x64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.osx-arm64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.osx-x64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.win-arm >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.win-arm64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.win-x64 >= 9.0.0, <= 9.0.17 9.0.18
Microsoft.NetCore.App.Runtime.win-x86 >= 9.0.0, <= 9.0.17 9.0.18

.NET 8.0

Package name Affected version Patched version
Microsoft.NetCore.App.Runtime.linux-arm >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.linux-arm64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.linux-musl-arm >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.linux-musl-arm64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.linux-musl-x64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.linux-x64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.osx-arm64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.osx-x64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.win-arm >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.win-arm64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.win-x64 >= 8.0.0, <= 8.0.28 8.0.29
Microsoft.NetCore.App.Runtime.win-x86 >= 8.0.0, <= 8.0.28 8.0.29

Advisory FAQ

How do I know if I am affected?

If using a package listed in affected packages, you're exposed to the vulnerability.

How do I fix the issue?

  1. To fix the issue please install the latest version of .NET. If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
  2. If your application references the vulnerable nuget package, update the package reference to the patched version. You can list the versions you have installed by running the dotnet --info command.

Once you have installed the updated runtime or SDK, restart your app

References