HomeMicrosoftCVE-2026-24836

CVE-2026-24836

HIGH
7.6CVSS
Published: 2026-01-28
Updated: 2026-01-29
AI Analysis

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and 10.2.0 contain a fix for the issue.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Attack Vector
network
Complexity
high
Privileges
high
User Action
required
Scope
changed
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-79

Metadata

Primary Vendor
MICROSOFT
Published
1/28/2026
Last Modified
1/29/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

Microsoft : Undergoing Analysis

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief