Junglewise Threat Intelligence

CVE-2026-47304: Microsoft .NET improper cryptographic signature verification

CVE-2026-47304 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Microsoft Visual Studio 2022. Vendors: Microsoft.

Executive brief

A security flaw exists in a .NET library used by developers to encrypt and decrypt XML data. An attacker could exploit this to bypass encryption protections, potentially allowing them to read or modify sensitive information that was supposed to be secure. This could lead to unauthorized data access or a breach of confidentiality for applications using this specific .NET component.

Technical details

A security feature bypass vulnerability exists in the EncryptedXml implementation within the System.Security.Cryptography.Xml package for .NET 8, 9, and 10. The root cause is improper verification of cryptographic signatures (CWE-347), which allows an attacker to bypass encryption protections. Exploitation requires a network-based attack with high complexity but no user interaction or prior privileges. Successful exploitation allows an attacker to access or modify encrypted data. Patches are available in versions 8.0.29, 9.0.18, and 10.0.10.

Affected products

  • Microsoft System.Security.Cryptography.Xml >= 8.0.0, <= 8.0.28
  • Microsoft System.Security.Cryptography.Xml >= 9.0.0, <= 9.0.17
  • Microsoft System.Security.Cryptography.Xml >= 10.0.0, <= 10.0.9

Timeline

  • 2026-07-14: disclosed: Initial advisory publication
  • 2026-07-20: advisory: GitHub Advisory updated

References

Related threats