Red Hat released Important security updates for .NET 10.0 on RHEL 8, RHEL 9, and RHEL 10, updating affected systems to SDK 10.0.111 and Runtime 10.0.11. The advisories remediate four vulnerabilities tracked as CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, and CVE-2026-62909, covering a security feature bypass, information disclosure, denial of service, and elevation of privilege in .NET. The fixes span multiple product variants and architectures, including x86_64, s390x, ppc64le, and aarch64, as well as extended support channels for older enterprise deployments.
A related Miracle Linux 8 advisory, surfaced through a Nessus local security check, flags the same .NET 10.0 and ASP.NET Core 10.0 package set as vulnerable and ties remediation to advisory AXSA-2026-1582. Tenable said the detection is based on installed package versions rather than active exploitation and noted that no known exploits are currently available. Together, the notices indicate coordinated downstream patching of the same four .NET flaws across Red Hat-compatible enterprise Linux distributions.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
A Miracle Linux 8 advisory, AXSA-2026-1582, was published for affected .NET 10.0 and ASP.NET Core 10.0 packages. The notice references the same four CVEs and is reflected in a Nessus local security check, which states no known exploits are available.
Red Hat published an Important security advisory for .NET 10.0 on Red Hat Enterprise Linux 10, updating the SDK to 10.0.111 and Runtime to 10.0.11. The advisory addresses CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, and CVE-2026-62909 across RHEL 10 channels and architectures.
Red Hat published an Important security advisory for .NET 10.0 on Red Hat Enterprise Linux 9, updating the SDK to 10.0.111 and Runtime to 10.0.11. The advisory fixes the same four .NET vulnerabilities across RHEL 9 product variants and architectures.
Red Hat published an Important security advisory for .NET 10.0 on Red Hat Enterprise Linux 8, updating the SDK to 10.0.111 and Runtime to 10.0.11. The update fixes CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, and CVE-2026-62909 across multiple RHEL 8 variants and architectures.
Fedora issued advisory FEDORA-2026-8b4cb2340a for Fedora 44's dotnet10.0 package. The advisory covers multiple vulnerabilities, including CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62909, and additional CVEs such as CVE-2026-70354.
The four .NET vulnerabilities referenced by the advisories were published, covering security feature bypass, information disclosure, denial of service, and elevation of privilege issues. This publication date is explicitly stated in the Miracle Linux Nessus plugin reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.