> USN-8740-1: .NET vulnerabilities
[DATE: 10/09/2026 06:57]
[LANGUAGE: EN]
Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did
not properly validate cross-origin WebSocket connections. An attacker could
possibly use this issue to expose sensitive information. (CVE-2026-58649)
Rajesh Chada discovered that the .NET watch AspireServerService improperly
exposed information through the use of certain arguments. An attacker could
possibly use this issue to elevate privileges and execute arbitrary code.
(CVE-2026-69806)