Red Hat released a broad set of Important security advisories for .NET 8.0, .NET 9.0, and .NET 10.0 across Red Hat Enterprise Linux 8, 9, and 10, including Extended Update Support, Extended Life Cycle, SAP Solutions, and CodeReady Linux Builder channels on x86_64, aarch64, ppc64le, and s390x. The updates deliver refreshed SDK and runtime builds such as .NET 8.0.130/8.0.30, .NET 9.0.120/9.0.19, and .NET 10.0.110/10.0.10, and remediate multiple vulnerability classes affecting .NET and ASP.NET Core, including denial of service, privilege escalation, authentication bypass, security feature bypass, information disclosure, spoofing, tampering, and local code execution.
The advisories highlight several notable flaws, including CVE-2026-50651, an HTTP/2 SETTINGS/PING ACK flood issue that can trigger out-of-memory conditions, CVE-2026-57108, a .NET Core type-confusion denial-of-service bug, and ASP.NET Core authentication-related privilege escalation issues such as CVE-2026-47300 and CVE-2026-47303. Red Hat said the fixes span numerous RHEL 9.4, 9.6, 10.0, and related support streams, and some packages also include a build-system improvement to reduce the time needed to detect hanging .NET RPM builds.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-24, Red Hat published RHSA-2026:58570, an Important advisory for .NET 9.0 on Red Hat Enterprise Linux 9.6 channels. The update delivers SDK 9.0.120 and Runtime 9.0.19 and addresses a large set of .NET and ASP.NET Core vulnerabilities.
On 2026-08-24, Red Hat published RHSA-2026:58567, an Important advisory for .NET 9.0 on Red Hat Enterprise Linux 10.0 Extended Update Support. The update provides SDK 9.0.120 and Runtime 9.0.19 and remediates numerous .NET and ASP.NET Core vulnerabilities.
On 2026-08-24, Red Hat published RHSA-2026:58569, an Important advisory for .NET 8.0 on Red Hat Enterprise Linux 9.6 channels. The update delivers SDK 8.0.130 and Runtime 8.0.30 and fixes multiple vulnerabilities, including denial-of-service, authentication bypass, spoofing, and local code execution issues.
On 2026-08-24, Red Hat published RHSA-2026:58568, an Important advisory for .NET 8.0 on Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related channels. The update provides SDK 8.0.130 and Runtime 8.0.30 and addresses multiple vulnerabilities across .NET, .NET Core, .NET Framework, and ASP.NET Core.
On 2026-08-24, Red Hat published RHSA-2026:58566, an Important advisory for .NET 8.0 on Red Hat Enterprise Linux 10.0 Extended Update Support. The update delivers SDK 8.0.130 and Runtime 8.0.30 and fixes a broad set of .NET and ASP.NET Core vulnerabilities, including newly listed information disclosure and elevation-of-privilege issues.
On 2026-07-20, Red Hat published RHSA-2026:41900, an Important advisory for .NET 10.0 on Red Hat Enterprise Linux 8. The update raises .NET to SDK 10.0.110 and Runtime 10.0.10 and addresses multiple security vulnerabilities.
On 2026-07-20, Red Hat published RHSA-2026:41897, an Important advisory for .NET 10.0 on Red Hat Enterprise Linux 10. The update provides SDK 10.0.110 and Runtime 10.0.10 and fixes multiple vulnerabilities across .NET, .NET Core, and ASP.NET Core.
On 2026-07-20, Red Hat published RHSA-2026:41898, an Important advisory for .NET 10.0 on Red Hat Enterprise Linux 9. The update delivers SDK 10.0.110 and Runtime 10.0.10 and addresses multiple vulnerabilities affecting .NET and ASP.NET Core components.
On 2026-07-20, Red Hat published RHSA-2026:41899, an Important advisory for .NET 9.0 on Red Hat Enterprise Linux 8. The release makes SDK 9.0.119 and Runtime 9.0.18 available and includes security fixes, bug fixes, and enhancements.
On 2026-07-20, Red Hat published RHSA-2026:41895, an Important advisory for .NET 9.0 on Red Hat Enterprise Linux 10. The update provides SDK 9.0.119 and Runtime 9.0.18 and remediates multiple security vulnerabilities across RHEL 10 and 10.2 channels.
On 2026-07-20, Red Hat published RHSA-2026:41896, an Important advisory for .NET 9.0 on Red Hat Enterprise Linux 9. The update delivers SDK 9.0.119 and Runtime 9.0.18 and fixes multiple vulnerabilities across .NET and ASP.NET Core components.
On 2026-07-20, Red Hat published RHSA-2026:41901, an Important advisory for .NET 8.0 on Red Hat Enterprise Linux 8. The update raises .NET to SDK 8.0.129 and Runtime 8.0.29 and addresses multiple security flaws affecting .NET, .NET Core, and ASP.NET Core.
On 2026-07-20, Red Hat published RHSA-2026:41893, an Important advisory for .NET 8.0 on Red Hat Enterprise Linux 10. The update provides SDK 8.0.129 and Runtime 8.0.29 and remediates multiple .NET and ASP.NET Core vulnerabilities across RHEL 10 and 10.2 channels.
On 2026-07-20, Red Hat published RHSA-2026:41894, an Important advisory for .NET 8.0 on Red Hat Enterprise Linux 9. The update delivers SDK 8.0.129 and Runtime 8.0.29 and fixes multiple .NET and ASP.NET Core vulnerabilities across RHEL 9 channels.
On 2026-06-19, Red Hat published RHSA-2026:27171 for Red Hat Hardened Images RPMs, providing updated .NET 9.0 and ASP.NET Core 9.0 packages for aarch64 and x86_64. The advisory addresses multiple CVEs and was later updated on 2026-07-15.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceimages.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.