Red Hat disclosed and remediated CVE-2026-50649, an Important .NET vulnerability caused by CWE-502 deserialization of untrusted data that can allow a local, unauthorized attacker to execute code. The company assigned the flaw a CVSS v3 score of 7.8 and said exploitation requires local access, low attack complexity, no privileges, and user interaction, with potential impact to confidentiality, integrity, and availability.
Affected products included multiple .NET package streams across Red Hat Enterprise Linux 8, 9, and 10, along with related extended support variants and Red Hat Hardened Images. Red Hat published security errata in July and August to deliver fixes across those product lines, while the underlying weakness reflects a broader class of unsafe deserialization bugs that can let attacker-controlled data trigger unintended object behavior and, in some cases, arbitrary code execution through gadget chains.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat published its CVE database entry for CVE-2026-50649, rating the .NET deserialization flaw as Important with a CVSS v3 score of 7.8. The entry links the issue to CWE-502 and documents affected and fixed Red Hat products.
On July 20, 2026, Red Hat published multiple RHSA advisories fixing CVE-2026-50649 across .NET package streams for Red Hat Enterprise Linux 8, 9, and 10. The advisories covered dotnet 8.0, 9.0, and 10.0 packages across those major versions.
The vulnerability was recorded in OSIDB Bzimport with Bugzilla ID 2500563. The record identifies the issue as local code execution in .NET via deserialization of untrusted data.
Red Hat states that CVE-2026-50649 was public on July 14, 2026. The flaw affects .NET and allows local code execution via deserialization of untrusted data.
Red Hat listed CVE-2026-50649 as fixed for Red Hat Hardened Images dotnet9-0-main in security advisory RHSA-2026:27171. This is the earliest dated remediation mentioned for the .NET deserialization flaw.
Red Hat later published additional errata addressing CVE-2026-50649 for Extended Update Support and SAP-focused RHEL variants, including RHSA-2026:58566 through RHSA-2026:58570. The references state these remediation notices were issued between July 20 and August 24, 2026, but do not anchor individual advisory dates in the content provided.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.