Microsoft disclosed CVE-2026-50525, a high-severity denial-of-service flaw in the .NET XML cryptography stack that can let an unauthenticated attacker crash or hang applications processing crafted XML. The issue affects System.Security.Cryptography.Xml, particularly EncryptedXml handling used in scenarios such as SAML assertions, WS-Security SOAP headers, and other encrypted XML endpoints exposed to untrusted networks. Malicious payloads with deeply nested encrypted elements, recursive structures, or abusive transform processing can trigger stack exhaustion, CPU starvation, or out-of-memory conditions; the vulnerability is tracked as CWE-770 and carries a CVSS 7.5 rating.
Microsoft's fix adds a default maximum recursion depth of 64 for recursive XML operations and blocks unsafe CipherReference transform methods unless an AppContext switch explicitly permits them. The runtime changes also cover decryption, canonicalization, signature computation, and signature verification paths, with tests for deep nesting, recursive encrypted payloads, infinite-loop XSLT, and expansion-style XSLT abuse. Organizations are advised to upgrade to patched .NET releases or update the System.Security.Cryptography.Xml NuGet package to prevent remote XML inputs from causing service disruption.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-50525 was publicly described as a high-severity denial-of-service vulnerability in Microsoft .NET's XML Cryptography stack, affecting System.Security.Cryptography.Xml and EncryptedXml processing. The disclosure states Microsoft addressed the issue by enforcing recursion-depth limits and restricting CipherReference transforms to a safe whitelist, and notes an NVD CVSS v3.1 score of 7.5.
A .NET runtime update introduced protections in System.Security.Cryptography.Xml, including a default maximum recursion depth of 64 and blocking unsafe encrypted XML transform methods unless explicitly allowed via an AppContext switch. The changes added tests for deep XML nesting, recursive encrypted payloads, and abusive XSLT scenarios tied to denial-of-service risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.