Microsoft .NET 9
Microsoft .NET 9
The Microsoft .NET 9 reaches end of service life on Nov 10, 2026. Third-party maintenance lets you keep it in service past that date and save 40-70% versus the OEM support contract.
Specifications
- product
- dotnet
- release
- 9
- product Label
- Microsoft .NET
- release Label
- 9
- codename
- lts
- latest Version
- 9.0.19
- release Date
- 2024-11-12
- maintained
- true
- source Url
- https://endoflife.date/dotnet
Lifecycle Dates
- End of Service Life
- Nov 10, 2026
- Last OEM Support
- Nov 10, 2026
OEM vs. 3rd Party Support
See how 3rd party maintenance compares to traditional OEM support for your Microsoft .NET 9. Get the same level of service at a fraction of the cost.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| 24/7/365 Support | ||
| Same-Day Parts Replacement | Limited | |
| Mixed-Vendor Support | ||
| Flexible Contract Terms | Annual Only | Month-to-Month Available |
| Asset Lifecycle Extension | ||
| OEM-Trained Engineers |
Why Choose 3rd Party Support for Microsoft .NET 9?
Save 40-70%
Dramatically reduce your maintenance costs while maintaining the same level of support coverage.
Extend Asset Life
Continue using your Microsoft .NET 9 well beyond the OEM end-of-life date.
24/7 Expert Support
OEM-trained engineers available around the clock with same-day parts replacement.
Microsoft .NET 9 Support: Frequently Asked Questions
Is the Microsoft .NET 9 still supported?
Yes, but OEM support for the Microsoft .NET 9 ends on Nov 10, 2026. You can renew with Microsoft or move to third-party maintenance and keep the same coverage at 40-70% lower cost.
When is the Microsoft .NET 9 end of service life (EOSL) date?
Microsoft lists the end of service life for the Microsoft .NET 9 as Nov 10, 2026.
Can I keep using the Microsoft .NET 9 after its EOSL date?
Yes. EOSL means Microsoft stops selling support contracts and issuing updates — the equipment itself keeps working. Third-party maintenance provides engineering support and replacement parts for as long as you choose to run it.
How much does third-party support for the Microsoft .NET 9 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Microsoft .NET 9
52 published CVEs affect the Microsoft .NET 9, including 45 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2024-43498 | CRITICAL | 9.8 | Nov 12, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-47303 | HIGH | 8.8 | Jul 14, 2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-47300 | HIGH | 8.8 | Jul 14, 2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-21176 | HIGH | 8.8 | Jan 14, 2025 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-50528 | HIGH | 8.2 | Jul 14, 2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-47304 | HIGH | 8.1 | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2025-26646 | HIGH | 8.0 | May 13, 2025 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-70354 | HIGH | 7.8 | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-62909 | HIGH | 7.8 | Aug 11, 2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62886 | HIGH | 7.8 | Aug 11, 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-62871 | HIGH | 7.8 | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-58641 | HIGH | 7.8 | Aug 11, 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-50650 | HIGH | 7.8 | Jul 14, 2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-50649 | HIGH | 7.8 | Jul 14, 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50646 | HIGH | 7.8 | Jul 14, 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-45490 | HIGH | 7.8 | Jun 9, 2026 | Improper authorization in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62901 | HIGH | 7.5 | Aug 11, 2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-62898 | HIGH | 7.5 | Aug 11, 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-50651 | HIGH | 7.5 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50648 | HIGH | 7.5 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |
Showing the 20 most severe of 52 known CVEs.
Get Third Party Support