Skip to content
anavem.com logoanavem.com logo
ResolvedMicrosoft .NET FrameworkHigh severityNewsCVE-2026-32178CVE-2026-32203CVE-2026-32226CVE-2026-23666CVE-2026-26171CVE-2026-33116Microsoft

KB5082424 Patches .NET Framework RCE and Five Other CVEs on Windows 11 23H2

April 2026 Patch Tuesday update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2 patches six CVEs including CVE-2026-32178 (RCE), three DoS, one security feature bypass, and one info disclosure.

On this page

Key takeaways

  • CVE-2026-32178: .NET Framework remote code execution.
  • CVE-2026-32203, CVE-2026-32226, CVE-2026-23666: three denial of service.
  • CVE-2026-26171: security feature bypass. CVE-2026-33116: info disclosure.
  • Superseded by KB5087058 (May 2026).

What to do now

High urgency
  1. Install KB5087058 (supersedes KB5082424).

Microsoft released KB5082424 on April 14, 2026, a cumulative update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2 patching six security vulnerabilities. Per the official KB, CVE-2026-32178 is a remote code execution flaw. Three additional CVEs address denial of service, one addresses security feature bypass, and one addresses information disclosure.

Six CVEs spanning RCE, DoS, bypass, and info disclosure make this a high-priority .NET Framework update. The RCE (CVE-2026-32178) is the most critical, per NinjaOne.

KB5082424 patches six .NET Framework CVEs including RCE on Windows 11 23H2.

Six .NET Framework CVEs: RCE (CVE-2026-32178), 3 DoS, 1 bypass, 1 info disclosure. Windows 11 23H2. Superseded by KB5087058.

Affected & context

Event summary

April 2026 .NET Framework cumulative update patching six CVEs including RCE on Windows 11 23H2.

Why it matters

RCE in .NET Framework enables code execution. Combined with DoS, bypass, and info disclosure across six CVEs.

Who is affected

Windows 11 23H2 with .NET Framework 3.5 or 4.8.1.

Vendors
Microsoft
Products
.NET Framework 3.5.NET Framework 4.8.1
CVEs
CVE-2026-32178CVE-2026-32203CVE-2026-32226CVE-2026-23666CVE-2026-26171CVE-2026-33116

KB5082424 Patches Six .NET Framework CVEs Including RCE

Microsoft released KB5082424 on April 14, 2026, a cumulative update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2. Per the official KB article, it patches six security vulnerabilities: CVE-2026-32178 (remote code execution), CVE-2026-32203, CVE-2026-32226, and CVE-2026-23666 (all denial of service), CVE-2026-26171 (security feature bypass), and CVE-2026-33116 (information disclosure).

Per NinjaOne, CVE-2026-32178 is the primary concern as it could allow attackers to execute arbitrary code with elevated privileges. The DoS vulnerabilities target various .NET Framework processing components. Microsoft reports no known issues.

RCE in .NET Framework Affects Enterprise Applications

CVE-2026-32178 (RCE) is the most critical fix. .NET Framework runs enterprise line-of-business applications across Windows 11 23H2 deployments. The combination of RCE, DoS, security bypass, and info disclosure covers multiple attack categories in a single update. Superseded by KB5087058 (May).

Windows 11 23H2 with .NET Framework

Windows 11 23H2 (22H2 editions also) with .NET Framework 3.5 or 4.8.1. Both x64 and ARM64. Automatic via Windows Update. Superseded by KB5087058 (May 2026). No known issues.

Timeline

  1. KB5082424 released

    Microsoft releases KB5082424 for .NET Framework on Windows 11 23H2.

    Source: Microsoft Support

    Confidence: High

  2. Superseded by KB5087058

    KB5087058 supersedes KB5082424 with two additional EoP fixes.

    Source: Microsoft Support

    Confidence: High

Impact

Six CVEs spanning RCE, DoS, security bypass, and info disclosure in .NET Framework.

Business impact

RCE enables arbitrary code execution. DoS flaws can crash .NET Framework apps.

Security impact

CVE-2026-32178 allows remote code execution in .NET Framework.

Affected audience: Windows 11 23H2 users with .NET Framework applications

Action required.

Technical details

CVEs
CVE-2026-32178, CVE-2026-32203, CVE-2026-32226, CVE-2026-23666, CVE-2026-26171, CVE-2026-33116
Patched versions
.NET Framework 4.8.1 (via KB5082424)

Response

Response status: Patched

Patch available: Yes

Workaround available: No

FAQ

What does KB5082424 fix?

Six CVEs: CVE-2026-32178 (RCE), CVE-2026-32203/32226/23666 (DoS), CVE-2026-26171 (security bypass), CVE-2026-33116 (info disclosure).

Is KB5082424 the latest update?

No. KB5087058 (May 2026) supersedes it with two additional EoP fixes.

Which systems are affected?

Windows 11 23H2 and 22H2 with .NET Framework 3.5 or 4.8.1, x64 and ARM64.

The bottom line

KB5082424 patches six .NET Framework CVEs including CVE-2026-32178 RCE on Windows 11 23H2. Superseded by KB5087058.

Six CVEs including RCE make this a critical .NET Framework update. Install KB5087058 (May) which supersedes it.

What happens next

KB5087058 (May) supersedes this update.

What to do

Install KB5087058 (supersedes KB5082424).

Sources

  1. Microsoft · Apr 14, 2026 · Primary source

    Claims supported
    • Six CVEs listed
    • No known issues
  2. NinjaOne · May 31, 2026

    Claims supported
    • CVE-2026-32178 is primary concern
Reader actions
Was this helpful?
Rate this articleRate
4 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.