Linuxsecurity Critical .NET Vulnerabilities in Ubuntu Affect Multiple Releases
Article Content
- •Two critical vulnerabilities in .NET affect multiple Ubuntu releases.
- •CVE-2026-45491 allows unauthorized file tampering, while CVE-2026-45591 can cause denial of service.
- •Users are urged to update their systems to the latest package versions to mitigate risks.
On June 9, 2026, two critical vulnerabilities in .NET were disclosed, affecting Ubuntu versions 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS. The vulnerabilities include CVE-2026-45491, which allows unauthorized file tampering, and CVE-2026-45591, which can lead to denial of service through excessive resource consumption. Attackers can exploit these flaws locally, posing a significant risk to systems using .NET CLI tools and runtime. Users are advised to update their systems to the latest package versions to mitigate these vulnerabilities. The vulnerabilities were confirmed by Ubuntu's security team and are part of a broader advisory for .NET users. A standard system update will address the issues.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-45491 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…