{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/wpf/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-50646"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft.WindowsDesktop.App.Runtime.win-arm64 (\u003e= 10.0.0, \u003c= 10.0.9)","Microsoft.WindowsDesktop.App.Runtime.win-x64 (\u003e= 10.0.0, \u003c= 10.0.9)","Microsoft.WindowsDesktop.App.Runtime.win-x86 (\u003e= 10.0.0, \u003c= 10.0.9)","Microsoft.WindowsDesktop.App.Runtime.win-arm64 (\u003e= 9.0.0, \u003c= 9.0.17)","Microsoft.WindowsDesktop.App.Runtime.win-x64 (\u003e= 9.0.0, \u003c= 9.0.17)","Microsoft.WindowsDesktop.App.Runtime.win-x86 (\u003e= 9.0.0, \u003c= 9.0.17)","Microsoft.WindowsDesktop.App.Runtime.win-arm64 (\u003e= 8.0.0, \u003c= 8.0.28)","Microsoft.WindowsDesktop.App.Runtime.win-x64 (\u003e= 8.0.0, \u003c= 8.0.28)","Microsoft.WindowsDesktop.App.Runtime.win-x86 (\u003e= 8.0.0, \u003c= 8.0.28)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","dotnet","wpf"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft has disclosed a remote code execution vulnerability (CVE-2026-50646) affecting the Windows Presentation Foundation (WPF) framework within .NET 8, .NET 9, and .NET 10. The vulnerability stems from an improper protection mechanism (CWE-693) during the parsing of XAML input. An attacker capable of delivering specially crafted XAML data to a vulnerable application can achieve arbitrary code execution in the context of the current user. This vulnerability impacts all architectures on Windows. Developers are required to update to the patched runtime versions and recompile any self-contained applications to remediate the risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to execute code as the user running the application, potentially leading to full system compromise or sensitive data exfiltration. The vulnerability affects a wide range of .NET desktop runtime versions, necessitating comprehensive patching across enterprise .NET environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all .NET environments to the latest runtime versions: .NET 8.0.29, .NET 9.0.18, or .NET 10.0.10.\u003c/li\u003e\n\u003cli\u003eFor applications deployed as self-contained bundles, recompile and redeploy all instances using the patched runtime.\u003c/li\u003e\n\u003cli\u003eUse the \u003ccode\u003edotnet --info\u003c/code\u003e command across endpoints to inventory and identify instances of vulnerable .NET SDKs and runtimes.\u003c/li\u003e\n\u003cli\u003eAudit applications that accept user-provided XAML input for potential exposure to untrusted data sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T21:53:53Z","date_published":"2026-09-08T21:53:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dotnet-wpf-rce/","summary":"A high-severity remote code execution vulnerability (CVE-2026-50646) in .NET WPF allows arbitrary code execution via maliciously crafted XAML input.","title":"Remote Code Execution in Windows Presentation Foundation","url":"https://feed.craftedsignal.io/briefs/2026-09-dotnet-wpf-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Wpf","version":"https://jsonfeed.org/version/1.1"}