You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This security update addresses a remote code execution vulnerability detailed in [CVE-2026-32178](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32178).
20
+
21
+
#### CVE-2026-32203 – Denial of Service vulnerability
22
+
23
+
This security update addresses a denial-of-service vulnerability detailed in [CVE-2026-32203](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32203).
24
+
25
+
#### CVE-2026-32226 – Denial of Service vulnerability
26
+
27
+
This security update addresses a denial-of-service vulnerability detailed in [CVE-2026-32226](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32226).
28
+
29
+
#### CVE-2026-23666 – Denial of Service vulnerability
30
+
31
+
This security update addresses a denial-of-service vulnerability detailed in [CVE-2026-23666](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23666).
This security update addresses a security feature bypass vulnerability detailed in [CVE-2026-26171](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26171).
36
+
37
+
#### CVE-2026-33116 – Information Disclosure vulnerability
38
+
39
+
This security update addresses an information disclosure vulnerability detailed in [CVE-2026-33116](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33116).
40
+
41
+
### Quality and reliability improvements
42
+
43
+
#### .NET Runtime
44
+
45
+
Addresses an issue to add verification logic for ClickOnce to support SHA384 and SHA512. (_Applies to: .NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1_)
46
+
47
+
Addresses an issue in cases where the Arm64 CLR could crash when code generates and catches a NullReferenceException within the same function. (_Applies to: .NET Framework 4.8.1_)
48
+
49
+
Addresses an issue to update operating system calls for compliance with current standards. (_Applies to: .NET Framework 4.8.1_)
50
+
51
+
#### WCF
52
+
53
+
Addresses an issue with running a WCF NamedPipe service inside a Win32 app container when running on Windows 11 or Windows Server 2025. (_Applies to: .NET Framework 4.8.1_)
54
+
55
+
## Known issues in this release
56
+
57
+
This release contains no known issues.
58
+
59
+
## Summary tables
60
+
61
+
The following table outlines the updates in this release.
The operating system rows list a KB that's used for update-offering purposes. When the operating system KB is offered, the applicability logic determines the specific .NET Framework updates that will be installed. Updates for individual .NET Framework versions are installed based on the version of .NET Framework that's already present on the device. Because of this, the operating system KB is not expected to be listed as an installed update on the device. The expected updates to be installed are the .NET Framework specific version updates listed in the preceding table.
107
+
108
+
This update installs the complete .NET Framework 3.5 product for Windows 11, version 26H1 (build version 28000) and newer. Unlike traditional cumulative updates that patch individual components, this delivers the full .NET Framework 3.5 product as a standalone installer. It replaces any previously installed version.
109
+
110
+
| Product version | .NET Framework 3.5 product update |
111
+
| --- | --- |
112
+
|**Windows 11, version 26H1**|[5084165](https://support.microsoft.com/kb/5084165)|
0 commit comments