StackDrift

End of life / .NET Core Runtime / 9.0

.NET Core Runtime 9.0 end of life

.NET Core Runtime 9.0 reaches end of life on 10 November 2026, in 65 days. 34 known CVEs reach this release, the most severe rated HIGH.

The detail

Released
12 November 2024
End of life
10 November 2026
Countdown
in 65 days
Status
Supported
Long term support
No
Newest build on this release
9.0.19
Newest release overall
10.0.11

CVEs that reach 9.0

Advisory Severity CVSS Published Fixed in
CVE-2026-47303
Microsoft Security Advisory CVE-2026-47303 | .NET Elevation of Privilege Vulnerability
HIGH 8.8 14 July 2026 9.0.18
CVE-2026-47300
Microsoft Security Advisory CVE-2026-47300 | .NET Elevation of Privilege Vulnerability
HIGH 8.8 14 July 2026 9.0.18
CVE-2026-50528
Microsoft Security Advisory CVE-2026-50528 | .NET Security Feature Bypass Vulnerability
HIGH 8.2 14 July 2026 9.0.18
CVE-2026-47304
Microsoft Security Advisory CVE-2026-47304 | .NET Security Feature Bypass Vulnerability
HIGH 8.1 14 July 2026 9.0.18
CVE-2026-70354
Microsoft Security Advisory CVE-2026-70354 | .NET Core Remote Code Execution Vulnerability
HIGH 7.8 11 August 2026 9.0.19
CVE-2026-50649
Microsoft Security Advisory CVE-2026-50649 | .NET Remote Code Execution Vulnerability
HIGH 7.8 14 July 2026 9.0.18
CVE-2026-50646
Microsoft Security Advisory CVE-2026-50646 | .NET Remote Code Execution Vulnerability
HIGH 7.8 14 July 2026 9.0.18
CVE-2026-62901
Microsoft Security Advisory CVE-2026-62901 | .NET Denial of Service Vulnerability
HIGH 7.5 11 August 2026 9.0.19
CVE-2026-62898
Microsoft Security Advisory CVE-2026-62898 | .NET Information Disclosure Vulnerability
HIGH 7.5 11 August 2026 9.0.19
CVE-2026-56170
Microsoft Security Advisory CVE-2026-56170 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.15
CVE-2026-50651
Microsoft Security Advisory CVE-2026-50651 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.18
CVE-2026-50648
Microsoft Security Advisory CVE-2026-50648 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.18
CVE-2026-50527
Microsoft Security Advisory CVE-2026-50527 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.18
CVE-2026-50525
Microsoft Security Advisory CVE-2026-50525 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.18
CVE-2026-50524
Microsoft Security Advisory CVE-2026-50524 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.18
CVE-2026-47302
Microsoft Security Advisory CVE-2026-47302 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.18
CVE-2026-57108
Microsoft Security Advisory CVE-2026-57108 | .NET Denial of Service Vulnerability
HIGH 7.5 14 July 2026 9.0.18
CVE-2026-45591
Microsoft Security Advisory CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability
HIGH 7.5 9 June 2026 9.0.17
CVE-2026-42899
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
HIGH 7.5 12 May 2026 9.0.16
CVE-2026-33116
Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
HIGH 7.5 14 April 2026 9.0.15
CVE-2026-32178
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
HIGH 7.5 14 April 2026 9.0.15
CVE-2026-26171
Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability
HIGH 7.5 14 April 2026 9.0.15
CVE-2026-26130
Microsoft Security Advisory CVE-2026-26130 – .NET Denial of Service Vulnerability
HIGH 7.5 10 March 2026 9.0.14
CVE-2026-26127
Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability
HIGH 7.5 10 March 2026 9.0.14
CVE-2025-30399
Microsoft Security Advisory CVE-2025-30399: .NET Remote Code Vulnerability
HIGH 7.5 10 June 2025 9.0.6
CVE-2025-26682
Microsoft Security Advisory CVE-2025-26682: .NET Denial of Service Vulnerability
HIGH 7.5 8 April 2025 9.0.4
CVE-2026-32177
Microsoft Security Advisory CVE-2026-32177 – .NET Elevation of Privilege Vulnerability
HIGH 7.3 12 May 2026 9.0.16
CVE-2026-35433
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
HIGH 7.3 12 May 2026 9.0.16
CVE-2026-62897
Microsoft Security Advisory CVE-2026-62897 | .NET Remote Code Execution Vulnerability
HIGH 7.0 11 August 2026 9.0.19
CVE-2026-50659
Microsoft Security Advisory CVE-2026-50659 | .NET Spoofing Vulnerability
MEDIUM 6.5 14 July 2026 9.0.18
CVE-2026-45491
Microsoft Security Advisory CVE-2026-45491 | .NET Tampering Vulnerability
MEDIUM 6.2 9 June 2026 9.0.17
CVE-2026-62899
Microsoft Security Advisory CVE-2026-62899 | .NET Security Feature Bypass Vulnerability
MEDIUM 5.9 11 August 2026 9.0.19
CVE-2025-55248
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
MEDIUM 4.8 14 October 2025 9.0.10
CVE-2026-32175
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
MEDIUM 4.3 12 May 2026 9.0.16

A further 14 advisories publish no version range, so whether they reach 9.0 cannot be determined from the advisory alone.

Where to move next

The newest tracked release is 10.0.11. If moving release is not an option yet, 9.0.19 is the newest build on the 9.0 line and needs no migration.

Other .NET Core Runtime releases

Vendor sources last checked 6 September 2026, and checked daily. This data last changed on 6 September 2026.

You just looked this up by hand, for one version

StackDrift scans your machines, works out every version you actually run, and mails you before the next support window closes or a CVE lands on a build you have deployed. It covers the runtimes, operating systems and kernels underneath your code, not just your packages.

See pricing