Microsoft confirmed that August 2026 .NET Framework security updates are causing some Windows Presentation Foundation (WPF) applications to fail when printing or exporting to PDF/XPS. The bug affects supported Windows 10, Windows 11, and Windows Server versions from 2012 through 2025, and is triggered in scenarios involving certain fonts or character sets, with Calibri specifically cited. Affected applications may throw System.IO.FileFormatException during printing or document generation.
Microsoft said it is investigating and published a temporary developer workaround that enables the AppContext switch Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection in application configuration. The company warned that the workaround disables protections added in the August update and could expose systems to vulnerabilities fixed that month, including flaws that may enable remote code execution or privilege escalation. Microsoft also advised against uninstalling the August .NET updates because removing them would reopen patched security issues.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed the issue in release health and updated release notes, saying it is investigating the problem. The company published a temporary workaround that enables the Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection AppContext switch, while warning that it disables protections added in the August 2026 update and should be used only when necessary.
Microsoft's August 2026 Patch Tuesday .NET Framework security updates introduced a side effect that causes some Windows Presentation Foundation applications to fail when printing or generating PDF/XPS content using certain fonts, including Calibri, sometimes with a System.IO.FileFormatException.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceheise.de
Open sourcebleepingcomputer.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.