Security researchers have disclosed a critical vulnerability in the .NET Framework's SoapHttpClientProtocol class, which is widely used in enterprise applications to handle SOAP messages. The flaw allows attackers to manipulate the target URL, enabling remote code execution (RCE) by redirecting SOAP requests to unintended destinations, such as local files or other protocols. Despite the severity and broad impact, Microsoft has reportedly declined to issue a fix, leaving numerous vendor and in-house solutions potentially exposed to exploitation.
The vulnerability has been demonstrated against several high-profile products, including Barracuda Service Center RMM (patched as CVE-2025-34392), Ivanti Endpoint Manager, Umbraco 8 CMS, Microsoft PowerShell, and Microsoft SQL Server Integration Services. Researchers warn that the list of affected products is likely much larger due to the prevalence of the vulnerable class in .NET-based codebases. The issue was presented at Black Hat Europe 2025, and while some vendors have issued patches, many applications remain at risk due to the underlying framework flaw and Microsoft's decision not to address it directly.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
watchTowr Labs published technical details on the SOAPwn issue, describing how hidden non-HTTP URL handling in .NET SOAP client proxies can be abused across many enterprise and in-house applications. The disclosure highlighted the broad impact beyond the specifically named products.
Microsoft repeatedly refused to treat the underlying .NET Framework behavior as a vulnerability, classifying it as an application-level issue and advising developers not to allow untrusted input into affected proxy classes. The company instead updated documentation rather than releasing a framework fix.
Barracuda and Ivanti issued fixes for their affected products, with the flaws tracked as CVE-2025-34392 for Barracuda Service Center RMM and CVE-2025-13659 for Ivanti Endpoint Manager. These vendor patches addressed product-level exposure stemming from the broader .NET behavior.
Researchers demonstrated exploitation paths against products including Barracuda Service Center RMM, Ivanti Endpoint Manager, Umbraco 8 CMS, Microsoft PowerShell, and SQL Server Integration Services, showing that rogue WSDL imports and proxy generation can lead to webshell upload or payload drops.
Security researchers, including Piotr Bazydło and watchTowr Labs, identified a design flaw in .NET Framework SOAP client proxy classes such as SoapHttpClientProtocol that allows attacker-controlled URLs to trigger arbitrary file writes, NTLM relay, and possible remote code execution in affected applications.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcego.theregister.com
Open sourcelabs.watchtowr.com
Open sourcethehackernews.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.