KB5087058 Patches Two .NET Framework EoP Flaws on Windows 11 23H2
May 2026 security update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2 patches CVE-2026-32177 and CVE-2026-35433, both elevation of privilege vulnerabilities. No quality improvements or known issues.

On this page
Key takeaways
- CVE-2026-32177: .NET Framework EoP.
- CVE-2026-35433: .NET Framework EoP.
- Windows 11 23H2, .NET Framework 3.5 and 4.8.1. No known issues.
What to do now
Medium urgency- Verify KB5087058 is installed via Windows Update.
Microsoft released KB5087058 on May 12, 2026, a security update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2. Per the official KB article, it patches CVE-2026-32177 and CVE-2026-35433, both elevation of privilege vulnerabilities in the .NET Framework runtime.
A lightweight security-only update with two EoP fixes for the legacy .NET Framework. No quality improvements or known issues.
KB5087058 patches two .NET Framework EoP vulnerabilities on Windows 11 23H2.
.NET Framework 3.5/4.8.1 on Win11 23H2. Two EoP CVEs. No quality changes. No known issues.
Affected & context
May 2026 .NET Framework security update patching CVE-2026-32177 and CVE-2026-35433 EoP on Windows 11 23H2.
EoP in .NET Framework can be exploited to escalate execution privileges.
Windows 11 23H2 with .NET Framework 3.5 or 4.8.1.
- Vendors
- Microsoft
- Products
- .NET Framework 3.5.NET Framework 4.8.1
- CVEs
- CVE-2026-32177CVE-2026-35433
KB5087058 Patches Two .NET Framework EoP Vulnerabilities
Microsoft released KB5087058 on May 12, 2026, a security update for .NET Framework 3.5 and 4.8.1 on Windows 11 23H2. Per Microsoft's KB article, it patches CVE-2026-32177 and CVE-2026-35433, both elevation of privilege vulnerabilities. No quality or reliability improvements are included.
This is a security-only update delivered via Windows Update, WSUS, and Microsoft Update Catalog. Microsoft reports no known issues. Supersedes KB5082424 (April 2026).
Legacy .NET Framework EoP Affects Enterprise LOB Apps
These are .NET Framework vulnerabilities (not .NET Core/.NET 8), affecting the legacy runtime used by many enterprise line-of-business applications. Elevation of privilege flaws in .NET Framework can be exploited to escalate from restricted to higher-privilege execution contexts.
Windows 11 23H2 with .NET Framework
Windows 11 23H2 with .NET Framework 3.5 or 4.8.1 installed. Automatic via Windows Update. Restart may be required if .NET Framework files are in use.
Timeline
KB5087058 released
Microsoft releases KB5087058 for .NET Framework on Windows 11 23H2.
Source: Microsoft Support
Confidence: High
Impact
Two .NET Framework EoP CVEs. Security-only, no quality changes.
Business impact
EoP vulnerabilities in .NET Framework affect enterprise LOB applications.
Affected audience: Windows 11 23H2 users with .NET Framework apps
Action required.
Technical details
- CVEs
- CVE-2026-32177, CVE-2026-35433
- Patched versions
- .NET Framework 4.8.1 (via KB5087058)
Response
Response status: Patched
Patch available: Yes
Workaround available: No
FAQ
What does KB5087058 fix?
CVE-2026-32177 and CVE-2026-35433, both elevation of privilege in .NET Framework 3.5 and 4.8.1.
Which systems need this update?
Windows 11 23H2 with .NET Framework 3.5 or 4.8.1 installed.
Are there known issues?
No. Microsoft reports no known issues.
The bottom line
KB5087058 patches CVE-2026-32177 and CVE-2026-35433 (EoP) in .NET Framework 3.5 and 4.8.1 for Windows 11 23H2.
Straightforward security update with two EoP fixes. No quality changes or known issues.
What happens next
July 2026 Patch Tuesday will include the next .NET Framework update.
What to do
Verify KB5087058 is installed on Windows 11 23H2 devices.
Sources
Microsoft · May 12, 2026 · Primary source
Claims supported
- CVE-2026-32177 and CVE-2026-35433
- No quality improvements
- No known issues