← All CVEs

CVE-2026-47304

HIGH 8.1

Published 2026-07-14 · Last modified 2026-07-21

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

ELEVATED IMPACT

Severe if exploited (CVSS 8.1), but no known exploitation and low modeled probability. Patch on a normal cadence.

Exploitation likelihood

0.2%chance of exploitation in 30 days · 10th percentile

○ In CISA KEV ○ Public exploit / PoC

Impact if exploited

8.1CVSS 3.1 · HIGH

  • ConfidentialityHigh
  • IntegrityHigh
  • AvailabilityHigh

What an attacker needs

  • Access: Reachable over the network — no local access needed
  • Privileges: No account or privileges required
  • User interaction: No user interaction needed
  • Complexity: Needs a race window or specific setup

✓ lowers the bar for an attacker · ⚠ raises it

Proof of concept & exploit code

Test against your own equipment

curl -s https://vulnpedia.com/cve/CVE-2026-47304/poc.jsonMachine-readable PoC index for this CVE (for automation).

Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-47304/poc.json

Affected

Vendors Microsoft

Products Microsoft Visual Studio 2017 Version 15.9 (Includes 15.0 15.8) Microsoft Visual Studio 2019 Version 16.11 (Includes 16.0 16.10) Microsoft Visual Studio 2022 Version 17.12 Microsoft Visual Studio 2022 Version 17.14 Microsoft Visual Studio 2026 Version 18.5 Microsoft Visual Studio 2026 Version 18.7

Weakness (CWE)

  • CWE-347: : Improper Verification of Cryptographic Signature
  • CWE-345: : Insufficient Verification of Data Authenticity

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

All CVSS metrics

  • HIGH 8.1 v3.1 · CNA Primary
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • HIGH 8.1 v3.1 · NVD Secondary
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Sources: NVD · CVE.org · EPSS