Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. Microsoft.Native.Quic.MsQuic.OpenSSL
  4. ›
  5. CVE-2026-62815

CVE-2026-62815: Microsoft QUIC: Remote Code Execution Vulnerability

September 8, 2026

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

References

  • github.com/advisories/GHSA-92f5-vc22-8j33
  • github.com/microsoft/msquic/commit/583e7d5b509bb0bfa3518482d98879b6eda41ad0
  • github.com/microsoft/msquic/commit/9ff06b71fd4b4d5258361598ada5b24cbc1beb20
  • github.com/microsoft/msquic/commit/e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3b
  • github.com/microsoft/msquic/pull/6217
  • github.com/microsoft/msquic/pull/6219
  • github.com/microsoft/msquic/pull/6220
  • github.com/microsoft/msquic/releases/tag/v2.4.19
  • github.com/microsoft/msquic/releases/tag/v2.5.10
  • github.com/microsoft/msquic/security/advisories/GHSA-92f5-vc22-8j33
  • msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815
  • nvd.nist.gov/vuln/detail/CVE-2026-62815

Code Behaviors & Features

Detect and mitigate CVE-2026-62815 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.4.19, all versions starting from 2.5.3 before 2.5.10

Fixed versions

  • 2.4.19
  • 2.5.10

Solution

Upgrade to versions 2.4.19, 2.5.10 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-416: Use After Free

Source file

nuget/Microsoft.Native.Quic.MsQuic.OpenSSL/CVE-2026-62815.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:20:13 +0000.