Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner, and JSON report output.
Critical (CVSS 9.8) — Deserialization of Untrusted Data (CWE-502) in Microsoft .NET Framework & .NET Runtime Patched: July 14, 2026 | Attributed to: Positive Technologies (PT-2026-60174)
CVE-2026-56158 is a critical remote code execution vulnerability in Microsoft .NET Framework and .NET runtime. The flaw exists in the unsafe deserialization of untrusted data (CWE-502) — when a .NET application uses legacy serializers (BinaryFormatter, NetDataContractSerializer, SoapFormatter, ObjectStateFormatter) or Json.NET with TypeNameHandling.All/Auto, an unauthenticated remote attacker can deliver a crafted serialized payload that triggers arbitrary code execution upon deserialization.
The vulnerability carries a CVSS 3.1 base score of 9.8 Critical with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning:
Microsoft released security updates on July 14, 2026 as part of the monthly Patch Tuesday cycle.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-56158 |
| Title | .NET Framework Remote Code Execution Vulnerability |
| CVSS 3.1 | 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| CVSS 2.0 | 7.5 High (AV:N/AC:L/Au:N/C:P/I:P/A:P) |
| CWE | CWE-502 (Deserialization of Untrusted Data) |
| Published | July 14, 2026 |
| Patched | July 14, 2026 |
| Discoverer | Positive Technologies (PT-2026-60174) |
| EPSS | Not scored yet |
| CISA KEV | Not listed |
The .NET runtime's legacy serializers reconstruct arbitrary object types from serialized streams without validating the type or content. When an attacker controls the serialized input, they can direct the deserializer to instantiate unexpected types whose constructors, callbacks, or property setters execute arbitrary code — a classic deserialization gadget chain attack.
The vulnerability affects multiple serialization mechanisms:
TypeConfuseDelegate gadget chain delegates to Process.StartProcessStartInfo embedded in SOAP bodyProcess.Start via ViewState field$type metadata when TypeNameHandling.All/Auto is enabled; ObjectDataProvider gadget calls Process.Start| Product | Vulnerable Range | Fixed Version | KB Article |
|---|---|---|---|
| .NET 8.0 | 8.0.0 – 8.0.28 | 8.0.29 | KB5100998 |
| .NET 9.0 | 9.0.0 – 9.0.17 | 9.0.18 | KB5100998 |
| .NET 10.0 | 10.0.0 – 10.0.9 | 10.0.10 | KB5101001 |
| .NET Framework 3.5 | All pre-patch | Patched | KB5100985 |
| .NET Framework 4.6.2–4.7.2 | All pre-patch | Patched | KB5100991 |
| .NET Framework 4.8 | All pre-patch | Patched | KB5101011 |
| .NET Framework 4.8.1 | All pre-patch | Patched | KB5101002 |
| Visual Studio 2022 (17.12) | Pre-patch | 17.12.x | — |
| Visual Studio 2022 (17.14) | Pre-patch | 17.14.x | — |
| Visual Studio 2026 (18.7) | Pre-patch | 18.7.x | — |
Alpine Linux packages:
dotnet8-runtime < 8.0.29-r0dotnet9-runtime < 9.0.18-r0dotnet10-runtime < 10.0.10-r0This PoC exploit generates and delivers payloads via 5 different deserialization attack formats:
Serialized Stream → BinaryFormatter.Deserialize() → TypeConfuseDelegate
→ Process.Start("cmd.exe", "/c calc.exe") → RCE
application/octet-streamActivitySurrogateSelector+ObjectSurrogate → TypeConfuseDelegate → Process.StartXML with type info → NetDataContractSerializer.ReadObject()
→ ProcessStartInfo instantiation → Process.Start → RCE
application/octet-stream or text/xmlSOAP envelope → SoapFormatter.Deserialize()
→ ProcessStartInfo in SOAP body → Process.Start → RCE
text/xmlViewState binary → ObjectStateFormatter.Deserialize()
→ Process.Start via ViewState field → RCE
application/octet-stream__VIEWSTATE fieldJSON with $type → JsonConvert.DeserializeObject<T>(json, TypeNameHandling.All)
→ ObjectDataProvider.MethodName = "Start" → Process.Start → RCE
$type metadataapplication/jsonTypeNameHandling.All or Auto┌─────────────────────────────────────────────────────────────────────┐
│ exploit.py │
├─────────────────────────────────────────────────────────────────────┤
│ │
│ ┌──────────────┐ ┌───────────────┐ ┌───────────────────────┐ │
│ │ PayloadGen │ │ PayloadDeliv │ │ VulnerabilityScanner │ │
│ │ │ │ │ │ │ │
│ │ • BinaryFmt │ │ • HTTP POST │ │ • HTTP header check │ │
│ │ • NetData │──▶│ • SOAP/WCF │──▶│ • Endpoint discovery │ │
│ │ • SoapFmt │ │ • JSON API │ │ • ViewState analysis │ │
│ │ • ObjectState│ │ • File save │ │ • Version detection │ │
│ │ • Json.NET │ │ │ │ │ │
│ └──────────────┘ └───────────────┘ └───────────────────────┘ │
│ │ │ │ │
│ └───────────────────┼──────────────────────┘ │
│ ▼ │
│ ┌──────────────┐ ┌──────────────────────────────────────────┐ │
│ │ PayloadList │ │ Report Generator (JSON) │ │
│ │ (Mock .NET) │ │ • CVE metadata, CVSS, CWE │ │
│ │ │ │ • Payload hashes (SHA-256) │ │
│ │ Simulates │ │ • Delivery results │ │
│ │ vulnerable │ │ • RCE confirmation │ │
│ │ deserialization│ │ • References │ │
│ └──────────────┘ └──────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────┘