Skip to content
anavem.com logoanavem.com logo
ResolvedMicrosoft .NET 8.0Medium severityNewsCVE-2026-26130Microsoft

KB5081277 Patches CVE-2026-26130 Denial of Service in .NET 8.0.25

March 2026 security update for .NET 8.0 patches CVE-2026-26130, a denial of service vulnerability. Updates to version 8.0.25. Superseded by .NET 8.0.28 (KB5097149).

On this page

Key takeaways

  • CVE-2026-26130: .NET Denial of Service vulnerability.
  • Updates .NET 8.0 to version 8.0.25.
  • Superseded by .NET 8.0.26 (April), 8.0.27 (May), 8.0.28 (June).

What to do now

Medium urgency
  1. Update to latest .NET 8.0 version.

Microsoft released KB5081277 on March 10, 2026, a security update for .NET 8.0 patching CVE-2026-26130, a denial of service vulnerability. Per the dotnet/core CVE tracking on GitHub, this is the only security fix in the March .NET 8.0 update, which brings the version to 8.0.25.

A lightweight security update with a single DoS CVE. Now four updates behind the latest .NET 8.0 release.

KB5081277 patches CVE-2026-26130 DoS in .NET 8.0.25.

.NET 8.0.25. Single CVE: CVE-2026-26130 DoS. All platforms. No known issues. Install 8.0.28+ instead.

Affected & context

Event summary

March 2026 .NET 8.0 security update patches CVE-2026-26130 DoS. Version 8.0.25.

Why it matters

DoS vulnerability affects .NET application availability. Single CVE, now superseded.

Who is affected

All .NET 8.0 installations before 8.0.25.

Vendors
Microsoft
Products
.NET 8.0 Runtime
CVEs
CVE-2026-26130

KB5081277 Patches .NET 8.0 Denial of Service Vulnerability

Microsoft released KB5081277 on March 10, 2026, a security update for .NET 8.0. Per the official dotnet/core CVE tracking on GitHub, the update patches CVE-2026-26130, a denial of service vulnerability in .NET. The update brings .NET 8.0 to version 8.0.25.

Per Microsoft's KB article, the 8.0.25 installation removes the previous .NET 8.0 version. The update applies to Windows (via Windows Update and WSUS), Linux, and macOS. Microsoft reported no known issues with this update.

Single DoS CVE in an Otherwise Lightweight Update

CVE-2026-26130 is a denial of service vulnerability affecting .NET applications. While less critical than code execution flaws, DoS vulnerabilities can crash production applications and disrupt service availability. This is the only security fix in the March 2026 .NET 8.0 update.

KB5081277 is now significantly outdated. Per the GitHub CVE list, subsequent updates patched additional vulnerabilities: .NET 8.0.26 (April) added four CVEs, .NET 8.0.27 (May) added four more, and .NET 8.0.28 (June) added three including CVE-2026-45591 in ASP.NET Core SignalR. Install the latest version.

All .NET 8.0 Platforms

All .NET 8.0 installations before 8.0.25 on Windows, Linux, macOS. Now superseded by .NET 8.0.28 (KB5097149, June) and .NET 8.0.29 (July). Install the latest available version from dotnet.microsoft.com.

Timeline

  1. KB5081277 released

    Microsoft releases .NET 8.0.25 with CVE-2026-26130 DoS fix.

    Source: Microsoft

    Confidence: High

Impact

Single DoS CVE in .NET 8.0. Now superseded by multiple later updates.

Business impact

DoS can crash production .NET applications.

Affected audience: .NET 8.0 operators

Action required.

Technical details

CVEs
CVE-2026-26130
Affected versions
.NET 8.0 (before 8.0.25)
Patched versions
.NET 8.0.25

Response

Response status: Patched

Patch available: Yes

Workaround available: No

FAQ

What does KB5081277 fix?

CVE-2026-26130, a .NET denial of service vulnerability. Updates to version 8.0.25.

Is this the latest .NET 8.0 update?

No. Install .NET 8.0.28 or later for complete protection. Multiple CVEs have been patched since March.

Which platforms are affected?

All .NET 8.0 installations before 8.0.25 on Windows, Linux, macOS.

The bottom line

KB5081277 patches CVE-2026-26130 (.NET DoS) in .NET 8.0.25. Single CVE, now superseded by multiple later updates.

Single DoS CVE. Install .NET 8.0.28 or later for latest protection including the June 2026 SignalR DoS fix.

What happens next

.NET 8.0.28 (June, KB5097149) and subsequent updates supersede this.

What to do

Update to latest .NET 8.0 from dotnet.microsoft.com.

Sources

  1. Microsoft · Mar 10, 2026 · Primary source

    Claims supported
    • Version 8.0.25
    • Security fixes
  2. Microsoft (GitHub) · Mar 10, 2026 · Primary source

    Claims supported
    • CVE-2026-26130 is the only CVE for .NET 8.0.25
    • Full CVE history for .NET 8.0
Reader actions
Was this helpful?
Rate this articleRate
8 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.