April 2026 Patch TuesdayKB5082421Normal patch window

Microsoft · KB5082421

Linked CVE review

Deploy Microsoft Developer Tools security update KB5082421

Linked CVEs
3
Confirmed exploited
0
PoC or lab evidence
0
Maximum CVSS
7.5
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
3 of 3 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-33116 Scheduled assessment
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

A flaw was found in .NET. A remote attacker could exploit this vulnerability by crafting a malicious XML document that triggers an infinite recursion within the XmlDecryptionTransform component. This could lead to a Denial of Service (DoS), making the affected system unresponsive.

7.5 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 2.44% · 83.8th percentileForecast date: 2026-10-06NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. RHSA-2026:13281: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
CVE-2026-23666 Scheduled assessment
.NET Framework Denial of Service Vulnerability

A flaw was found in .NET Framework. An unauthorized attacker can exploit a race condition, which is a concurrent execution using shared resources with improper synchronization, to deny service over a network. This vulnerability can lead to a Denial of Service (DoS) for affected systems.

7.5 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.33% · 70.1th percentileForecast date: 2026-10-06NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-32226 Scheduled assessment
.NET Framework Denial of Service Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

5.9 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.66% · 49.7th percentileForecast date: 2026-10-06NETWORK · HIGH complexity · NONE privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.