Edit

July 2026 cumulative update

Released July 14, 2026

Summary of what's new in this release

Security improvements

CVE-2026-47302 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-47302.

CVE-2026-47304 – .NET Framework Security Feature Bypass vulnerability

This security update addresses a security feature bypass vulnerability detailed in CVE-2026-47304.

CVE-2026-50304 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50304.

CVE-2026-50324 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50324.

CVE-2026-50355 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50355.

CVE-2026-50368 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50368.

CVE-2026-50411 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50411.

CVE-2026-50525 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50525.

CVE-2026-50527 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50527.

CVE-2026-50646 – .NET Framework Elevation of Privilege vulnerability

This security update addresses an elevation of privilege vulnerability detailed in CVE-2026-50646.

CVE-2026-50647 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50647.

CVE-2026-50648 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50648.

CVE-2026-50649 – .NET Framework Remote Code Execution vulnerability

This security update addresses a remote code execution vulnerability detailed in CVE-2026-50649.

CVE-2026-50650 – .NET Framework Elevation of Privilege vulnerability

This security update addresses an elevation of privilege vulnerability detailed in CVE-2026-50650.

CVE-2026-50652 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50652.

CVE-2026-50653 – .NET Framework Denial of Service vulnerability

This security update addresses a denial of service vulnerability detailed in CVE-2026-50653.

CVE-2026-50659 – .NET Framework Tampering vulnerability

This security update addresses a tampering vulnerability detailed in CVE-2026-50659.

CVE-2026-56158 – .NET Framework Remote Code Execution vulnerability

This security update addresses a remote code execution vulnerability detailed in CVE-2026-56158.

Quality and reliability improvements

.NET Libraries

  • Addresses an issue with synchronous HttpWebRequest connections where requests could hang in specific secure connection scenarios with certain server configurations.

.NET Runtime

  • Addresses an issue in the Visual Studio x86 native debugger where certain floating-point values could be reported incorrectly during step operations in mixed-code applications.

Known issues in this release

This release contains no known issues.

Summary tables

The following table outlines the updates in this release.

Product version Cumulative update
Windows 11, version 26H1
.NET Framework 4.8.1 5101002
Windows 11, version 25H2
.NET Framework 3.5, 4.8.1 5100998
Windows 11, version 24H2
.NET Framework 3.5, 4.8.1 5101001
Microsoft server operating system, version 24H2
.NET Framework 3.5, 4.8.1 5100998
Microsoft server operating system, version 23H2
.NET Framework 3.5, 4.8.1 5100999
Windows 11, version 22H2 and Windows 11, version 23H2
.NET Framework 3.5, 4.8.1 5101004
Windows Server 2022 5102206
.NET Framework 3.5, 4.8 5101010
.NET Framework 3.5, 4.8.1 5101005
Windows 10, version 22H2 5102203
.NET Framework 3.5, 4.8 5101006
.NET Framework 3.5, 4.8.1 5101000
Windows 10, version 21H2 5102202
.NET Framework 3.5, 4.8 5101006
.NET Framework 3.5, 4.8.1 5101000
Windows 10 1809 and Windows Server 2019 5102201
.NET Framework 3.5, 4.7.2 5100989
.NET Framework 3.5, 4.8 5101008
Windows 10 1607 and Windows Server 2016
.NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2 5099535
.NET Framework 4.8 5101007

The following table is for earlier Windows and Windows Server versions for Security and Quality Rollup updates.

Product version Security and quality rollup
Windows Server 2012 R2 5102205
.NET Framework 3.5 5100985
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2 5100991
.NET Framework 4.8 5101011
Windows Server 2012 5102204
.NET Framework 3.5 5100986
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2 5100990
.NET Framework 4.8 5101009

The operating system rows list a KB that's used for update-offering purposes. When the operating system KB is offered, the applicability logic determines the specific .NET Framework updates that will be installed. Updates for individual .NET Framework versions are installed based on the version of .NET Framework that's already present on the device. Because of this, the operating system KB is not expected to be listed as an installed update on the device. The expected updates to be installed are the .NET Framework specific version updates listed in the preceding table.

This update installs the complete .NET Framework 3.5 product for Windows 11, version 26H1 (build version 28000) and newer. Unlike traditional cumulative updates that patch individual components, this delivers the full .NET Framework 3.5 product as a standalone installer. It replaces any previously installed version.

Product version .NET Framework 3.5 product update
Windows 11, version 26H1 5101014