Critical .NET Vulnerabilities in Ubuntu Expose Sensitive Information

Critical .NET Vulnerabilities in Ubuntu Expose Sensitive Information

First seen 10 Sep 2026, 15:20 UTC UbuntuLinuxsecurity 57.8

Article Content

Browse articles
ThreatCluster

On September 8, 2026, two critical vulnerabilities (CVE-2026-58649 and CVE-2026-69806) were disclosed in .NET components used in Ubuntu systems. Weeraphat Srisutham identified a flaw in the .NET watch BrowserRefreshServer that fails to validate cross-origin WebSocket connections, potentially allowing attackers to expose sensitive information. Additionally, Rajesh Chada found that the .NET watch AspireServerService improperly exposes information, enabling privilege escalation and arbitrary code execution. Affected systems include Ubuntu 26.04 LTS, 24.04 LTS, and 22.04 LTS. Users are advised to update to the latest package versions to mitigate these vulnerabilities. The issues were publicly disclosed on September 8, 2026, and patches are available as of today, September 10, 2026.

Key Points: • Two critical vulnerabilities in .NET affect multiple Ubuntu LTS versions. • CVE-2026-58649 allows information exposure via WebSocket connections. • CVE-2026-69806 enables privilege escalation and arbitrary code execution.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-58649 published
Weeraphat Srisutham discovered a flaw in .NET watch BrowserRefreshServer allowing sensitive information exposure.
Linuxsecurity
2026-09-08
CVE-2026-69806 published
Rajesh Chada identified a vulnerability in .NET watch AspireServerService that could lead to privilege escalation.
Linuxsecurity
2026-09-10
Patches released
Ubuntu released updates for affected .NET packages to address the vulnerabilities.
Ubuntu