End of life / .NET Core Runtime / 9.0
.NET Core Runtime 9.0 end of life
.NET Core Runtime 9.0 reaches end of life on 10 November 2026, in 65 days. 34 known CVEs reach this release, the most severe rated HIGH.
The detail
- Released
- 12 November 2024
- End of life
- 10 November 2026
- Countdown
- in 65 days
- Status
- Supported
- Long term support
- No
- Newest build on this release
- 9.0.19
- Newest release overall
- 10.0.11
CVEs that reach 9.0
| Advisory | Severity | CVSS | Published | Fixed in |
|---|---|---|---|---|
| CVE-2026-47303 Microsoft Security Advisory CVE-2026-47303 | .NET Elevation of Privilege Vulnerability | HIGH | 8.8 | 14 July 2026 | 9.0.18 |
| CVE-2026-47300 Microsoft Security Advisory CVE-2026-47300 | .NET Elevation of Privilege Vulnerability | HIGH | 8.8 | 14 July 2026 | 9.0.18 |
| CVE-2026-50528 Microsoft Security Advisory CVE-2026-50528 | .NET Security Feature Bypass Vulnerability | HIGH | 8.2 | 14 July 2026 | 9.0.18 |
| CVE-2026-47304 Microsoft Security Advisory CVE-2026-47304 | .NET Security Feature Bypass Vulnerability | HIGH | 8.1 | 14 July 2026 | 9.0.18 |
| CVE-2026-70354 Microsoft Security Advisory CVE-2026-70354 | .NET Core Remote Code Execution Vulnerability | HIGH | 7.8 | 11 August 2026 | 9.0.19 |
| CVE-2026-50649 Microsoft Security Advisory CVE-2026-50649 | .NET Remote Code Execution Vulnerability | HIGH | 7.8 | 14 July 2026 | 9.0.18 |
| CVE-2026-50646 Microsoft Security Advisory CVE-2026-50646 | .NET Remote Code Execution Vulnerability | HIGH | 7.8 | 14 July 2026 | 9.0.18 |
| CVE-2026-62901 Microsoft Security Advisory CVE-2026-62901 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 11 August 2026 | 9.0.19 |
| CVE-2026-62898 Microsoft Security Advisory CVE-2026-62898 | .NET Information Disclosure Vulnerability | HIGH | 7.5 | 11 August 2026 | 9.0.19 |
| CVE-2026-56170 Microsoft Security Advisory CVE-2026-56170 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.15 |
| CVE-2026-50651 Microsoft Security Advisory CVE-2026-50651 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-50648 Microsoft Security Advisory CVE-2026-50648 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-50527 Microsoft Security Advisory CVE-2026-50527 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-50525 Microsoft Security Advisory CVE-2026-50525 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-50524 Microsoft Security Advisory CVE-2026-50524 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-47302 Microsoft Security Advisory CVE-2026-47302 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-57108 Microsoft Security Advisory CVE-2026-57108 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-45591 Microsoft Security Advisory CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 9 June 2026 | 9.0.17 |
| CVE-2026-42899 Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 12 May 2026 | 9.0.16 |
| CVE-2026-33116 Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | HIGH | 7.5 | 14 April 2026 | 9.0.15 |
| CVE-2026-32178 Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability | HIGH | 7.5 | 14 April 2026 | 9.0.15 |
| CVE-2026-26171 Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability | HIGH | 7.5 | 14 April 2026 | 9.0.15 |
| CVE-2026-26130 Microsoft Security Advisory CVE-2026-26130 – .NET Denial of Service Vulnerability | HIGH | 7.5 | 10 March 2026 | 9.0.14 |
| CVE-2026-26127 Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability | HIGH | 7.5 | 10 March 2026 | 9.0.14 |
| CVE-2025-30399 Microsoft Security Advisory CVE-2025-30399: .NET Remote Code Vulnerability | HIGH | 7.5 | 10 June 2025 | 9.0.6 |
| CVE-2025-26682 Microsoft Security Advisory CVE-2025-26682: .NET Denial of Service Vulnerability | HIGH | 7.5 | 8 April 2025 | 9.0.4 |
| CVE-2026-32177 Microsoft Security Advisory CVE-2026-32177 – .NET Elevation of Privilege Vulnerability | HIGH | 7.3 | 12 May 2026 | 9.0.16 |
| CVE-2026-35433 Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability | HIGH | 7.3 | 12 May 2026 | 9.0.16 |
| CVE-2026-62897 Microsoft Security Advisory CVE-2026-62897 | .NET Remote Code Execution Vulnerability | HIGH | 7.0 | 11 August 2026 | 9.0.19 |
| CVE-2026-50659 Microsoft Security Advisory CVE-2026-50659 | .NET Spoofing Vulnerability | MEDIUM | 6.5 | 14 July 2026 | 9.0.18 |
| CVE-2026-45491 Microsoft Security Advisory CVE-2026-45491 | .NET Tampering Vulnerability | MEDIUM | 6.2 | 9 June 2026 | 9.0.17 |
| CVE-2026-62899 Microsoft Security Advisory CVE-2026-62899 | .NET Security Feature Bypass Vulnerability | MEDIUM | 5.9 | 11 August 2026 | 9.0.19 |
| CVE-2025-55248 Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability | MEDIUM | 4.8 | 14 October 2025 | 9.0.10 |
| CVE-2026-32175 Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability | MEDIUM | 4.3 | 12 May 2026 | 9.0.16 |
A further 14 advisories publish no version range, so whether they reach 9.0 cannot be determined from the advisory alone.
Where to move next
The newest tracked release is 10.0.11. If moving release is not an option yet, 9.0.19 is the newest build on the 9.0 line and needs no migration.
Other .NET Core Runtime releases
Vendor sources last checked 6 September 2026, and checked daily. This data last changed on 6 September 2026.
You just looked this up by hand, for one version
StackDrift scans your machines, works out every version you actually run, and mails you before the next support window closes or a CVE lands on a build you have deployed. It covers the runtimes, operating systems and kernels underneath your code, not just your packages.