LiveActive security incident?Get immediate response
CVE Record

CVE-2026-33116: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2026-33116 is a denial-of-service flaw in Microsoft .NET, .NET Framework, and the vendor-titled Visual Studio advisory. An unauthenticated network attacker could make affected software stop serving users. It does not indicate data theft or code execution, but availability impact is rated high.

Executive priority

Prioritize patching exposed .NET services in the current maintenance cycle. Escalate faster for customer-facing, revenue-critical, or uptime-sensitive systems because the main business risk is service disruption, not confirmed compromise.

Technical view

The source bundle describes an infinite-loop condition reachable over the network without authentication or user interaction. CVSS 3.1 is 7.5 with high availability impact only. Listed weakness categories include improper input handling, uncontrolled resource consumption, XML entity expansion, and infinite loop.

Likely exposure

Exposure is likely where affected .NET or .NET Framework versions run network-reachable applications that process untrusted input. The bundle lists .NET 8.0, 9.0.0, 10.0.0, and multiple .NET Framework 3.5, 4.7.x, 4.8, and 4.8.1 configurations.

Exploitation context

The bundle marks KEV as false and CVSS exploit maturity as unproven. No cited source in the bundle confirms active exploitation. Treat this as a credible network DoS risk because attack complexity and privileges required are low.

Researcher notes

The public bundle gives impact, CVSS, CWE mapping, affected products, and vendor references, but not the exact vulnerable parser or trigger condition. Avoid assuming exploit mechanics. Validation should focus on version exposure, reachability, and vendor-fixed build confirmation.

Mitigation direction

  • Apply Microsoft updates referenced by the MSRC advisory.
  • For Red Hat-packaged .NET, apply the relevant RHSA errata.
  • Prioritize internet-facing or business-critical .NET services first.
  • Check vendor guidance before using workarounds not named in sources.
  • Monitor service availability after patching.

Validation and detection

  • Inventory installed .NET runtimes, SDKs, Framework versions, and Visual Studio dependencies.
  • Map affected versions to internet-facing and partner-facing services.
  • Confirm Microsoft or Red Hat fixed packages are installed.
  • Run regression tests for patched .NET applications.
  • Review monitoring for recurring availability failures.
Prepared
Confidence
medium
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-20: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-400: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-776: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-835: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-33116 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
5Timeline events
2ADP providers
22Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C3.93.6microsoft
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6redhat-SADP

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2026-33116Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. ADP timelineredhat-SADP

    Reported to Red Hat.

  3. CVE publishedCVE Program

    The CVE record was published.

  4. ADP timelineredhat-SADP

    Made public.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
redhat-SADPdotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform
other:Red Hat severity ratingcvssV3_1
  • 2026-04-13T05:12:13.834Z: Reported to Red Hat.
  • 2026-04-14T18:38:58.320Z: Made public.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Microsoft.NET 10.010.0.0Listed
Microsoft.NET 8.08.0Listed
Microsoft.NET 8.08.0.0Listed
Microsoft.NET 9.09.0.0Listed
MicrosoftMicrosoft .NET Framework 3.53.5.0Listed
MicrosoftMicrosoft .NET Framework 3.5 AND 4.7.24.7.0Listed
MicrosoftMicrosoft .NET Framework 3.5 AND 4.84.8.0Listed
MicrosoftMicrosoft .NET Framework 3.5 AND 4.8.14.8.1Listed
MicrosoftMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.24.7.0Listed
MicrosoftMicrosoft .NET Framework 4.84.8.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.