KB5104032: .NET 8.0.29 July 2026 Security Update — 16 CVEs Fixed, Automatic Repair Loop Reported, and How to Install

If you saw “2026-07 .NET 8.0.29 Security Update for x64 Client (KB5104032)” appear in your Windows Update queue on July 14, 2026 and were not sure what it was or whether to install it, this guide explains everything.

KB5104032 is Microsoft’s July 2026 security update for .NET 8.0, updating the runtime to version 8.0.29. It shipped on Patch Tuesday, July 14, 2026 — the same day as the main Windows 11 update KB5101650 and the .NET Framework update KB5100998. It fixes 16 security vulnerabilities across the .NET 8.0 runtime and is only offered to devices that have .NET 8.0 already installed.

One known issue has been reported: at least one user experienced an automatic repair loop after installing KB5104032 on July 15, 2026. Here is everything you need to know.

What Is KB5104032?

KB5104032 is the July 14, 2026 security servicing update for .NET 8.0, advancing the runtime to version 8.0.29. Its full name in Windows Update is “2026-07 .NET 8.0.29 Security Update for x64 Client (KB5104032).”

Before going further, an important distinction worth making clear.

KB5104032 is NOT the same as KB5100998.

These two updates appeared on the same Patch Tuesday and both relate to .NET — but they address completely different runtimes.

KB5100998 covers .NET Framework 3.5 and 4.8.1 — the classic Windows-bundled .NET Framework that has been part of Windows since the early 2000s. Every Windows system has this installed as a built-in component.

KB5104032 covers .NET 8.0 — Microsoft’s modern, cross-platform .NET runtime that is installed separately from Windows. Not every PC has .NET 8.0 — only systems where applications requiring .NET 8.0 have been installed will have it, and only those systems will be offered KB5104032.

If KB5104032 did not appear in your Windows Update, it simply means your PC does not have .NET 8.0 installed. This is not a problem.

What Is .NET 8.0?

.NET 8.0 is Microsoft’s eighth major release of the modern .NET platform — the unified, cross-platform successor to both .NET Framework and .NET Core. Released in November 2023, it is a Long-Term Support (LTS) release, meaning Microsoft provides three years of support for it.

Unlike .NET Framework, which ships as part of Windows, .NET 8.0 is installed separately — either by users who download it directly or automatically when an application requires it. Common .NET 8.0 applications include modern desktop apps, ASP.NET Core web applications, game engines built on .NET, and many developer tools.

Applications built on .NET 8.0 may include productivity software, creative tools, developer environments, and increasingly, AI-powered desktop applications. As the AI software ecosystem expands, more applications are being built on modern .NET runtimes rather than the classic .NET Framework.

.NET 8.0 servicing updates are upgrades. The latest servicing update for 8.0 will remove the previous 8.0 update upon successful installation. For example, when .NET 8.0.29 is installed, .NET 8.0.28 will be removed from the computer if it is present. This means KB5104032 replaces whatever previous .NET 8.0 version was installed.

Every CVE Fixed by KB5104032

KB5104032 addresses 16 security vulnerabilities in the .NET 8.0 runtime. Here is every CVE the update patches.

CVE-2026-47300 — Security vulnerability in the .NET 8.0 runtime. Part of the batch of vulnerabilities discovered in Microsoft’s pre-Patch-Tuesday security audit cycle.

CVE-2026-47302 — A denial of service vulnerability also addressed in the .NET Framework update KB5100998 — the same CVE appears in both updates because it affects code shared between .NET Framework and the modern .NET runtime.

CVE-2026-47303 — A vulnerability in .NET 8.0’s runtime components requiring security remediation as part of the July 2026 cycle.

CVE-2026-50524 — Security vulnerability in .NET 8.0 runtime components patched in this servicing update.

CVE-2026-50525 — Denial of service vulnerability in .NET 8.0’s network communication components. Also appears in KB5100998 for .NET Framework.

CVE-2026-50526 — A vulnerability in .NET 8.0 runtime components addressed in July 2026.

CVE-2026-50527 — Denial of service vulnerability affecting .NET 8.0 runtime. Also addressed in KB5100998 for .NET Framework.

CVE-2026-50528 — Security vulnerability in the .NET 8.0 runtime patched in this update.

CVE-2026-50646 — A vulnerability specific to the .NET 8.0 runtime not present in .NET Framework.

CVE-2026-50648 — Security vulnerability addressed in July 2026 .NET runtime updates.

CVE-2026-50649 — A .NET 8.0 runtime vulnerability patched as part of this servicing release.

CVE-2026-50650 — Security vulnerability in .NET 8.0 components addressed in KB5104032.

CVE-2026-50651 — A vulnerability in .NET 8.0 runtime patched in July 2026.

CVE-2026-50659 — Security vulnerability in .NET 8.0 addressed in this servicing update.

CVE-2026-56170 — A vulnerability in .NET 8.0 runtime components included in the July 2026 fix batch.

CVE-2026-57108 — The final CVE in KB5104032’s fix list, addressed as part of the comprehensive July 2026 .NET 8.0 security update.

Quick CVE Summary Table

CVEShared with KB5100998?
CVE-2026-47300No
CVE-2026-47302Yes
CVE-2026-47303No
CVE-2026-50524No
CVE-2026-50525Yes
CVE-2026-50526No
CVE-2026-50527Yes
CVE-2026-50528No
CVE-2026-50646No
CVE-2026-50648No
CVE-2026-50649No
CVE-2026-50650No
CVE-2026-50651No
CVE-2026-50659No
CVE-2026-56170No
CVE-2026-57108No

Three CVEs appear in both KB5104032 and KB5100998 because those vulnerabilities affect code paths shared between the modern .NET 8.0 runtime and the classic .NET Framework. If you have both runtimes installed, both updates are needed to fully close those shared vulnerabilities.

Known Issue — Automatic Repair Loop

One confirmed user issue has been reported following KB5104032 installation.

A user reported on July 15, 2026 — one day after the update released — that the .NET 8.0.29 update specifically caused their laptop’s boot process to hang and stall. The system then repeatedly cycled into Automatic Repair Mode and would hang there as well.

The user described: “Not the first time, but the recent .NET update (2026-07 .NET 8.0.29 Security Update for x64 Client (KB5104032)) forced the boot up to hang and stall. After a restart, system repeatedly recycled into Automatic Repair Mode and would hang there also.”

Microsoft’s community support acknowledged the issue and expressed sympathy, noting the difficulty of the situation — the user was unable to access Windows, boot into Safe Mode, uninstall the updates, restore the system, or complete a reset.

This is a serious reported issue but appears to affect a limited subset of hardware configurations. NinjaOne’s monitoring rates KB5104032 as appearing stable at approximately 70% probability of successful installation and continued operation — reflecting that most installations succeed but a meaningful minority may encounter problems.

If you are experiencing the automatic repair loop after KB5104032:

The standard recovery approach when Safe Mode and Windows recovery options are unavailable is to boot from Windows installation media and use the repair options from there. Create a Windows installation USB on another PC, boot from it on the affected machine, select Repair Your Computer, then Troubleshoot, Advanced Options, Uninstall Updates. Remove KB5104032 as the latest installed quality update.

If Uninstall Updates does not appear or does not work, try System Restore from the same Advanced Options menu — if a restore point exists from before July 14, restoring to it will roll back KB5104032 alongside any other July updates installed at the same time.

Which Windows Versions and Architectures Does KB5104032 Apply To?

This update is available on Microsoft Update for Windows client operating systems and available on WSUS and MU Catalog for Windows Server operating systems. This update will be offered if you have .NET 8.0 installed on a supported version of Windows.

KB5104032 applies across a broad range of Windows versions — including Windows 10 1507, 1607, 1703, 1709, 1803, and later, through to Windows 11 versions 22H2, 23H2, 24H2, and 25H2, plus Windows Server versions. The determining factor is not which Windows version you are on — it is whether .NET 8.0 is installed on your system.

Available architectures: x64 (64-bit Intel/AMD), ARM64 (ARM-based devices).

How to Check If .NET 8.0 Is Installed

Before worrying about KB5104032, verify whether .NET 8.0 is on your system.

Method 1 — Command Prompt or PowerShell

Open Command Prompt or PowerShell and run:

dotnet --list-runtimes

Look for any entry beginning with “Microsoft.NETCore.App 8.0” in the output. If it is present, .NET 8.0 is installed and KB5104032 applies to your system.

Method 2 — Settings

Go to Settings, Apps, Installed apps. Search for “.NET” in the search box. Any installed .NET 8.x runtime will appear in the list.

Method 3 — Windows Update History

If KB5104032 appears in your Windows Update History with a Successfully installed status, .NET 8.0 was on your system and the update applied correctly.

How to Install KB5104032

Method 1 — Windows Update (Recommended)

Go to Settings, Windows Update, Check for updates. If your system has .NET 8.0 installed, KB5104032 will appear alongside other July 2026 updates. Click Download and install. A restart may be required if any affected .NET runtime files are in use at the time of installation.

Method 2 — Microsoft Update Catalog

Go to catalog.update.microsoft.com. Search for KB5104032. Download the package matching your system architecture — x64 or ARM64. Run the downloaded file and follow the prompts.

If you encounter error 0x80244022 when downloading through Windows Update, our complete fix guide covers every solution.

Restart requirement:

You may need to restart the computer after applying this update if any affected files are being used. If .NET 8.0 applications are running when the update installs, Windows will schedule the file replacement for the next restart.

KB5104032 and the July 2026 Update Stack

On July 14, 2026, most Windows systems with .NET installed received three separate .NET-related updates alongside the main Windows update.

KB5101650 — The main Windows 11 July 2026 cumulative security update. 570 vulnerabilities fixed, Point-in-Time Restore, Bluetooth improvements. This is the operating system update.

KB5104032 — .NET 8.0.29 security update. 16 CVEs fixed in the modern .NET 8.0 runtime. Only installs if .NET 8.0 is present.

KB5100998 — .NET Framework 3.5 and 4.8.1 security update. 9 CVEs fixed in the classic Windows-bundled .NET Framework. Ships to all systems regardless of whether .NET 8.0 is installed.

KB5104033 — .NET 9.0.18 security update. Ships alongside KB5104032 for systems that have .NET 9.0 installed.

KB890830 — Windows Malicious Software Removal Tool v5.143. The monthly MSRT update, shipped alongside every Patch Tuesday.

A Windows system with both .NET Framework and .NET 8.0 installed would receive all five of these updates on July 14. A system with only .NET Framework would receive KB5101650, KB5100998, and KB890830 but not KB5104032.

Should You Install KB5104032?

Yes — if you have .NET 8.0 installed.

The 16 CVEs fixed in KB5104032 include denial of service vulnerabilities and security vulnerabilities in .NET 8.0 runtime components. Applications built on .NET 8.0 that process external input — web requests, file parsing, API responses — are the most exposed surface for these vulnerabilities. Leaving KB5104032 uninstalled means those vulnerabilities remain exploitable in any .NET 8.0 application running on your system.

Consider a brief wait if:

You are running a laptop or PC configuration where the July 2026 update cycle has already caused instability — particularly if you also experienced issues with KB5101650. Given the automatic repair loop report, monitoring community reports for your specific hardware configuration for a few days before installing is a reasonable precaution.

Consider pausing if:

Your system runs critical .NET 8.0 applications in a production environment where downtime risk outweighs the vulnerability exposure. In that case, test KB5104032 on a non-production system first before rolling it out to critical infrastructure.

Do not skip indefinitely:

.NET 8.0.29 replaces .NET 8.0.28 upon installation. Microsoft does not provide long-term cumulative patches for skipped .NET 8.0 servicing versions — eventually applying a future .NET 8.0 update will also include KB5104032’s security content anyway. There is no sustainable path to avoiding this update’s security fixes.

Frequently Asked Questions

What is KB5104032?

KB5104032 is Microsoft’s July 14, 2026 security servicing update for .NET 8.0, updating the runtime to version 8.0.29. It fixes 16 security vulnerabilities in the .NET 8.0 runtime and is available for all Windows versions where .NET 8.0 is installed.

Is KB5104032 the same as KB5100998?

No. KB5104032 updates the modern .NET 8.0 runtime — separately installed software used by modern applications. KB5100998 updates .NET Framework 3.5 and 4.8.1 — the classic Windows-bundled .NET Framework present on all Windows systems. Both appeared on the same July 14, 2026 Patch Tuesday but address completely different components.

Why did KB5104032 not appear in my Windows Update?

KB5104032 only appears if .NET 8.0 is already installed on your system. If you have not installed any applications requiring .NET 8.0, it will not be offered. Run “dotnet –list-runtimes” in Command Prompt to check whether .NET 8.0 is present.

How many vulnerabilities does KB5104032 fix?

KB5104032 fixes 16 CVEs in the .NET 8.0 runtime, including CVE-2026-47300, CVE-2026-47302, CVE-2026-47303, CVE-2026-50524 through CVE-2026-50528, CVE-2026-50646 through CVE-2026-50651, CVE-2026-50659, CVE-2026-56170, and CVE-2026-57108.

Does KB5104032 cause an automatic repair loop?

At least one user reported an automatic repair loop after installing KB5104032 on July 15, 2026. NinjaOne rates the update as approximately 70% stable, meaning most installations succeed but a subset may encounter problems. If you experience this issue, boot from Windows installation media and use the Uninstall Updates or System Restore options from the Advanced recovery menu.

Does KB5104032 require a restart?

A restart may be required if any .NET 8.0 runtime files are in use at the time of installation. If .NET 8.0 applications are actively running, Windows will schedule file replacement for the next system restart.

What .NET version does KB5104032 install?

KB5104032 updates .NET 8.0 to version 8.0.29. It replaces .NET 8.0.28 upon successful installation — the previous version is automatically removed as part of the upgrade process.

What is KB5104033 and how is it related to KB5104032?

KB5104033 is the July 2026 security update for .NET 9.0, updating it to version 9.0.18. It shipped on the same July 14, 2026 Patch Tuesday as KB5104032. Both are modern .NET runtime updates — KB5104032 for .NET 8.0, KB5104033 for .NET 9.0. Systems with both runtimes installed would receive both updates.

Leave a Reply

Your email address will not be published. Required fields are marked *