CVE-2026-62886-- .NET Framework Elevation of Privilege vulnerability

SSRao 1 Reputation point
2026-09-23T01:54:28.1533333+00:00

Hi MS, I wanted to bring to your attention that KB5126144 installed successfully but System.web.dll file version under v2.0.50727 path remains unpatched (CVE-2026-62886)
R7 scanner continues to flag the server because the file version at this specific path has not advanced ->
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.web.dll

at first I though it is isolated case but found that all the servers with .Net3.5 are impacted
is this known issue? how to fix it?

Windows for business | Windows Server | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments

2 answers

Sort by: Most helpful
  1. SSRao 1 Reputation point
    2026-09-24T01:31:14.1+00:00

    Thanks for insights but I curious only servers with .Net3.5 Framework were flagged. this means the old dormant files of v2.0 are still sitting inside that path because MS didn't purge them. Will MS fix this metadate file in next update

    Was this answer helpful?


  2. Daphne Huynh (WICLOUD CORPORATION) 1,570 Reputation points Microsoft External Staff Moderator
    2026-09-23T02:11:54.9966667+00:00

    Welcome to Microsoft Q&A!

    Thank you for taking the time to provide detailed information about your environment and the results you've observed.

    Based on the information currently available, this does not appear to be a documented known issue with KB5126144. Microsoft indicates that the September 2026 update addresses CVE-2026-62886 and does not list any known issues related to this release.

    One detail that may help with troubleshooting is that KB5126144 serves as the umbrella update for Windows Server 2019. Depending on the .NET Framework versions installed on the server, Windows will apply one of the following component updates:

    • KB5126043 for .NET Framework 3.5 and 4.7.2
    • KB5126048 for .NET Framework 3.5 and 4.8

    Because of this, checking only for KB5126144 or relying on a single DLL version may not be enough to confirm that the security update has been fully applied.

    To help verify the installation, I would recommend you check the following:

    1. Ensure the server has been restarted after the update installation.
    2. Confirm that KB5126043 or KB5126048 is installed successfully:

    dism /online /get-packages /format:table | findstr "5126043 5126048"

    1. Verify the file version of System.Web.dll in both Framework locations:

    (Get-Item "$env:windir\Microsoft.NET\Framework\v2.0.50727\System.Web.dll").VersionInfo.FileVersion

    (Get-Item "$env:windir\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll").VersionInfo.FileVersion

    1. Compare the reported file versions with the file information published in the applicable KB article.
    2. If the expected package or file version is missing, try reinstalling the applicable update from the Microsoft Update Catalog and then restart the server.

    As a best practice, I would recommend not manually replacing or copying System.Web.dll from another server. This file is serviced through Windows and the .NET Framework servicing stack, and manual replacement can lead to inconsistencies in the component store.

    If the applicable update is installed successfully and the DLL version matches Microsoft's published file information, but Rapid7 continues to report CVE-2026-62886, it may be worth opening a case with Rapid7 and providing the installed package information and file version details for review of the detection logic.

    On the other hand, if the installed file version does not match the version expected in the Microsoft update package, I recommend you opening a Microsoft support case so the servicing state of the affected servers can be investigated further.

    References: September 8, 2026-KB5126144 Cumulative Update for .NET Framework 3.5, 4.7.2 and 4.8 for Windows 10, version 1809 and Windows Server 2019 | Microsoft Support

    September 2026 cumulative update - .NET Framework | Microsoft Learn

    Microsoft Update Catalog

    If you find it useful, please click Accept Answer.

    Thank you for choosing Microsoft Q&A.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.