Microsoft .NET Vulnerability CVE-2026-71328 Disclosed

Microsoft .NET Vulnerability CVE-2026-71328 Disclosed

First seen 10 Sep 2026, 11:15 UTC Advisories.Gitlabgithub.comnvd.nist.gov 57.1

Article Content

Browse articles
ThreatCluster

Microsoft has published a security advisory for a critical vulnerability in Microsoft.DiaSymReader.Native, identified as CVE-2026-71328. This vulnerability allows for an out-of-bounds write while processing MSFZ PDB files, affecting any Microsoft .NET project that uses the impacted package versions. Developers are advised to update to version 18.9.0-beta1.26405.2 or later of the affected package. The vulnerability has a CVSS score of 7.5, indicating high severity, with potential impacts on confidentiality, integrity, and availability. Users are encouraged to report any security issues to the Microsoft Security Response Center. The advisory was published on September 8, 2026, and is currently available on GitHub and GitLab.

Key Points: • CVE-2026-71328 is a critical vulnerability in Microsoft.DiaSymReader.Native. • Affected projects must update to version 18.9.0-beta1.26405.2 or later to mitigate risks. • The vulnerability has a CVSS score of 7.5, indicating significant potential impact.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-71328 published
Microsoft disclosed a vulnerability in Microsoft.DiaSymReader.Native affecting .NET projects.
github.com
2026-09-10
Advisory released
Microsoft released guidance for developers on how to address the vulnerability.
github.com
2026-09-10
GitLab advisory published
GitLab published an advisory detailing the same vulnerability and mitigation steps.
Advisories.Gitlab