KB5104033: what it fixes and who gets it
KB5104033 is a security update from Microsoft's July 2026 release for .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows.
Should you install it?
Yes. It is a routine security update; none of its fixes are rated Critical or reported as exploited. Windows Update installs it automatically on supported home PCs.
If the installation fails or the PC misbehaves afterwards, note the exact error code first: the fix depends on it. Our update troubleshooting guides are linked on this page.
Security fixes in KB5104033
| CVE | Type | CVSS | Severity |
|---|---|---|---|
| CVE-2026-47300ASP.NET Core Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-47303ASP.NET Core Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-50528.NET Security Feature Bypass Vulnerability | Security Feature Bypass | 8.2 | Important |
| CVE-2026-47304.NET Security Feature Bypass Vulnerability | Security Feature Bypass | 8.1 | Important |
| CVE-2026-50646.NET Framework Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important |
| CVE-2026-50649.NET Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important |
| CVE-2026-50650.NET Framework Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-47302.NET Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-50524.NET Framework Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-50525.NET Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-50527.NET Framework Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-50648.NET Framework Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-50651.NET Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-56170ASP.NET Core Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-57108.NET Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-50526.NET Tampering Vulnerability | Tampering | 7.0 | Important |
| CVE-2026-50659.NET Spoofing Vulnerability | Spoofing | 6.5 | Important |
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
…