KB5082424 Patches .NET Framework RCE and Five Other CVEs on Windows 11 23H2
April 2026 Patch Tuesday update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2 patches six CVEs including CVE-2026-32178 (RCE), three DoS, one security feature bypass, and one info disclosure.

On this page
Key takeaways
- CVE-2026-32178: .NET Framework remote code execution.
- CVE-2026-32203, CVE-2026-32226, CVE-2026-23666: three denial of service.
- CVE-2026-26171: security feature bypass. CVE-2026-33116: info disclosure.
- Superseded by KB5087058 (May 2026).
What to do now
High urgency- Install KB5087058 (supersedes KB5082424).
Microsoft released KB5082424 on April 14, 2026, a cumulative update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2 patching six security vulnerabilities. Per the official KB, CVE-2026-32178 is a remote code execution flaw. Three additional CVEs address denial of service, one addresses security feature bypass, and one addresses information disclosure.
Six CVEs spanning RCE, DoS, bypass, and info disclosure make this a high-priority .NET Framework update. The RCE (CVE-2026-32178) is the most critical, per NinjaOne.
KB5082424 patches six .NET Framework CVEs including RCE on Windows 11 23H2.
Six .NET Framework CVEs: RCE (CVE-2026-32178), 3 DoS, 1 bypass, 1 info disclosure. Windows 11 23H2. Superseded by KB5087058.
Affected & context
April 2026 .NET Framework cumulative update patching six CVEs including RCE on Windows 11 23H2.
RCE in .NET Framework enables code execution. Combined with DoS, bypass, and info disclosure across six CVEs.
Windows 11 23H2 with .NET Framework 3.5 or 4.8.1.
- Vendors
- Microsoft
- Products
- .NET Framework 3.5.NET Framework 4.8.1
- CVEs
- CVE-2026-32178CVE-2026-32203CVE-2026-32226CVE-2026-23666CVE-2026-26171CVE-2026-33116
KB5082424 Patches Six .NET Framework CVEs Including RCE
Microsoft released KB5082424 on April 14, 2026, a cumulative update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2. Per the official KB article, it patches six security vulnerabilities: CVE-2026-32178 (remote code execution), CVE-2026-32203, CVE-2026-32226, and CVE-2026-23666 (all denial of service), CVE-2026-26171 (security feature bypass), and CVE-2026-33116 (information disclosure).
Per NinjaOne, CVE-2026-32178 is the primary concern as it could allow attackers to execute arbitrary code with elevated privileges. The DoS vulnerabilities target various .NET Framework processing components. Microsoft reports no known issues.
RCE in .NET Framework Affects Enterprise Applications
CVE-2026-32178 (RCE) is the most critical fix. .NET Framework runs enterprise line-of-business applications across Windows 11 23H2 deployments. The combination of RCE, DoS, security bypass, and info disclosure covers multiple attack categories in a single update. Superseded by KB5087058 (May).
Windows 11 23H2 with .NET Framework
Windows 11 23H2 (22H2 editions also) with .NET Framework 3.5 or 4.8.1. Both x64 and ARM64. Automatic via Windows Update. Superseded by KB5087058 (May 2026). No known issues.
Timeline
KB5082424 released
Microsoft releases KB5082424 for .NET Framework on Windows 11 23H2.
Source: Microsoft Support
Confidence: High
Superseded by KB5087058
KB5087058 supersedes KB5082424 with two additional EoP fixes.
Source: Microsoft Support
Confidence: High
Impact
Six CVEs spanning RCE, DoS, security bypass, and info disclosure in .NET Framework.
Business impact
RCE enables arbitrary code execution. DoS flaws can crash .NET Framework apps.
Security impact
CVE-2026-32178 allows remote code execution in .NET Framework.
Affected audience: Windows 11 23H2 users with .NET Framework applications
Action required.
Technical details
- CVEs
- CVE-2026-32178, CVE-2026-32203, CVE-2026-32226, CVE-2026-23666, CVE-2026-26171, CVE-2026-33116
- Patched versions
- .NET Framework 4.8.1 (via KB5082424)
Response
Response status: Patched
Patch available: Yes
Workaround available: No
FAQ
What does KB5082424 fix?
Six CVEs: CVE-2026-32178 (RCE), CVE-2026-32203/32226/23666 (DoS), CVE-2026-26171 (security bypass), CVE-2026-33116 (info disclosure).
Is KB5082424 the latest update?
No. KB5087058 (May 2026) supersedes it with two additional EoP fixes.
Which systems are affected?
Windows 11 23H2 and 22H2 with .NET Framework 3.5 or 4.8.1, x64 and ARM64.
The bottom line
KB5082424 patches six .NET Framework CVEs including CVE-2026-32178 RCE on Windows 11 23H2. Superseded by KB5087058.
Six CVEs including RCE make this a critical .NET Framework update. Install KB5087058 (May) which supersedes it.
What happens next
KB5087058 (May) supersedes this update.
What to do
Install KB5087058 (supersedes KB5082424).
Sources
Microsoft · Apr 14, 2026 · Primary source
Claims supported
- Six CVEs listed
- No known issues
NinjaOne · May 31, 2026
Claims supported
- CVE-2026-32178 is primary concern