Note
- Release Date:
August 11, 2026 - Version:
.NET Framework 3.5, 4.7.2 and 4.8
Summary
This article describes the security and cumulative update for 3.5, 4.7.2 and 4.8 for Windows 10, version 1809 and Windows Server 2019.
Security Improvements
CVE-2026-65810 - .NET Framework Elevation of Privilege vulnerability
This security update addresses an elevation of privilege vulnerability detailed in CVE-2026-65810.
CVE-2026-62872 - .NET Framework Elevation of Privilege vulnerability
This security update addresses an elevation of privilege vulnerability detailed in CVE-2026-62872.
CVE-2026-62886 - .NET Framework Remote Code Execution vulnerability
This security update addresses a remote code execution vulnerability detailed in CVE-2026-62886.
CVE-2026-62897 - .NET Framework Remote Code Execution vulnerability
This security update addresses a remote code execution vulnerability detailed in CVE-2026-62897.
CVE-2026-70354 - .NET Framework Remote Code Execution vulnerability
This security update addresses a remote code execution vulnerability detailed in CVE-2026-70354.
CVE-2026-62902 - .NET Framework Information Disclosure vulnerability
This security update addresses an information disclosure vulnerability detailed in CVE-2026-62902.
Quality and Reliability Improvements
For a list of improvements that were released with this update, please see the article links in the Additional Information section of this article.
Known issues in this update
Known Issues: After installing the August 2026 .NET Framework cumulative update, some WPF applications may fail with a System.IO.FileFormatException when printing or generating PDF/XPS content that uses certain fonts, including Calibri.
Workaround: Applications may mitigate the issue by enabling the Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection AppContext switch in the app config file, as shown below.
<configuration>
<runtime>
<AppContextSwitchOverrides
value="Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection=true"/>
</runtime>
</configuration>
This switch disables security protections introduced in the August 2026 update and may increase exposure to the vulnerabilities addressed by that update. Microsoft recommends using this workaround only as a temporary measure and only when required to address this issue.
Status: This issue is resolved in the September 2026 .NET Framework cumulative update and later updates. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
Known Issues: After installing the August 2026 .NET Framework cumulative update, WPF applications that print—or display print preview—from an in-memory XPS document registered with System.IO.Packaging.PackageStore may fail with a System.IO.FileFormatException while the document is loading. This occurs when the package identity used as both the PackageStore key and the XpsDocument package identity is an absolute URI that uses the pack scheme—for example, pack://<guid>.xps. Images and fonts contained within the same XPS package are then incorrectly rejected as being outside the package. Application code and XPS content do not need to have changed for this failure to occur.
Workaround: Applications that can be rebuilt should use an absolute package identity that does not use the pack scheme—for example, xpspack://<guid>.xps. This resolves the failure while keeping the protections introduced in the August 2026 update enabled. For applications that cannot be rebuilt, enable the Switch.System.Windows.DisableXpsPackageBoundaryRestriction AppContext switch in the application configuration file:
<configuration>
<runtime>
<AppContextSwitchOverrides
value="Switch.System.Windows.DisableXpsPackageBoundaryRestriction=true"/>
</runtime>
</configuration>
This switch disables security protections introduced in the August 2026 update and may increase exposure to the vulnerabilities addressed by that update. Microsoft recommends using this workaround only as a temporary measure and only when required to address this issue.
Status: Investigating.
Additional information about this update
The following articles contain additional information about this update as it relates to individual product versions.
- 5120698 Description of the Cumulative Update for .NET Framework 3.5 and 4.7.2 for Windows 10, version 1809 and Windows Server 2019 (KB5120698)
- 5120703 Description of the Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10, version 1809 and Windows Server 2019 (KB5120703)
How to get this update
| Release Channel | Available | Next Step |
|---|---|---|
| Windows Update and Microsoft Update | Yes | None. This update will be downloaded and installed automatically from Windows Update. |
| Windows Update for Business | Yes | None. This update will be downloaded and installed automatically from Windows Update. |
| Microsoft Update Catalog | Yes | To get the standalone package for this update, go to the Microsoft Update Catalog website. |
| Windows Server Update Services (WSUS) | Yes | This operating system update will offer, as applicable, and individual .NET Framework product updates will be installed. For more information about individual .NET Framework product updates see additional information about this update section. This update will automatically sync with WSUS if you configure as follows: Product: Windows 10, version 1809 and Windows Server 2019 Classification: Security Updates |
How to obtain help and support for this update
- Help for installing updates: Windows Update FAQ
- Protect yourself online and at home: Windows Security support
- Local support according to your country/region/region: International Support