KB5101002: what it fixes and who gets it

KB5101002 is a security update from Microsoft's July 2026 release for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1, Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 and other products.

Microsoft data read
17CVEs fixed
0rated Critical
0already exploited
Norestart required

Should you install it?

Yes. It is a routine security update; none of its fixes are rated Critical or reported as exploited. Windows Update installs it automatically on supported home PCs.

If the installation fails or the PC misbehaves afterwards, note the exact error code first: the fix depends on it. Our update troubleshooting guides are linked on this page.

Security fixes in KB5101002

CVETypeCVSSSeverity
CVE-2026-47304.NET Security Feature Bypass VulnerabilitySecurity Feature Bypass8.1Important
CVE-2026-50646.NET Framework Remote Code Execution VulnerabilityRemote Code Execution7.8Important
CVE-2026-50649.NET Remote Code Execution VulnerabilityRemote Code Execution7.8Important
CVE-2026-50650.NET Framework Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-47302.NET Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50304Windows Active Directory Federation Services Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50355Windows Active Directory Federation Services Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50368Windows Active Directory Federation Services Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50411Windows Active Directory Federation Services Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50525.NET Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50527.NET Framework Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50647Active Directory Federation Server Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50648.NET Framework Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50652Azure Active Directory Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50653Azure Active Directory Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50659.NET Spoofing VulnerabilitySpoofing6.5Important
CVE-2026-50324Windows Active Directory Federation Services Denial of Service VulnerabilityDenial of Service5.9Important

Questions and experiences

Ask about this page: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

4,322 members already hereThey read, write, comment and vote. 0 verified · 31 joined this year

Cookies

We use essential cookies to run the platform. Analytics and marketing cookies are only turned on once you consent — you can change your choice at any time.