Red Hat has released security updates for multiple .NET and ASP.NET Core vulnerabilities affecting dotnet packages in Red Hat Enterprise Linux 8, 9, and 10, including Extended Update Support and SAP-focused releases. The patched issues include CVE-2026-47300, an ASP.NET Core privilege-escalation flaw caused by an incorrect authentication algorithm; CVE-2026-47303, an authentication-bypass issue tied to assumed-immutable data that can also lead to privilege escalation; CVE-2026-57108, a .NET Core type-confusion bug that allows remote denial of service; and CVE-2026-50651, a .NET HTTP/2 flaw in SocketsHttpHandler Http2Connection where a SETTINGS/PING ACK flood can trigger out-of-memory conditions.
Red Hat rates the ASP.NET Core flaws as Important with CVSS 8.8, while the two denial-of-service issues carry CVSS 7.5 ratings. According to Red Hat, the privilege-escalation bugs can be exploited by an authorized attacker over the network, while the denial-of-service flaws are remotely reachable and require no privileges, with the HTTP/2 issue specifically enabling resource exhaustion through uncontrolled allocation. Fixes were issued through multiple RHSA advisories beginning in July 2026 and extended with additional updates for supported RHEL maintenance channels, including RHEL 10.0 EUS, RHEL 9.6 EUS, and RHEL 9.4 Update Services for SAP Solutions.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On July 20, 2026, Red Hat released RHSA advisories for RHEL 8, 9, and 10 covering CVE-2026-50651, CVE-2026-47300, CVE-2026-57108, and CVE-2026-47303 across dotnet 8.0, 9.0, and 10.0 package streams. The advisories included RHSA-2026:41893, 41895, 41897, 41899, 41900, 41901, 41894, and 41896.
Red Hat published CVE-2026-47303, an Important-severity ASP.NET Core authentication-bypass flaw that can lead to privilege escalation by manipulating assumed-immutable data. Red Hat assigned it a CVSS v3 score of 8.8 and linked it to Bugzilla 2500502.
Red Hat published CVE-2026-57108, an Important-severity .NET Core type-confusion vulnerability that allows an unauthenticated remote attacker to cause denial of service. The issue is mapped to CWE-843 and linked to Bugzilla 2500109.
Red Hat published CVE-2026-47300, an Important-severity ASP.NET Core privilege-escalation vulnerability caused by an incorrect authentication algorithm implementation. Red Hat assigned it a CVSS v3 score of 8.8 and linked it to Bugzilla 2500492.
Red Hat made public CVE-2026-50651, a .NET denial-of-service flaw involving an HTTP/2 SETTINGS/PING ACK flood that can cause out-of-memory conditions. The issue is associated with Bugzilla 2499217.
On August 24, 2026, Red Hat published additional advisories for RHEL 10.0 Extended Update Support, RHEL 9.4 Update Services for SAP Solutions, and RHEL 9.6 Extended Update Support addressing the same four vulnerabilities. The additional advisories included RHSA-2026:58566, 58567, 58568, 58569, and 58570.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.