Microsoft August 2026 .NET Update Breaks Printing & PDF Export in WPF Apps
What Happened — A cumulative .NET Framework update released in August 2026 caused WPF‑based applications to throw System.IO.FileFormatException when printing or generating PDF/XPS files that use certain fonts (e.g., Calibri). Microsoft issued a temporary workaround that disables a new font‑handling protection, which itself re‑exposes the system to the very vulnerabilities the update was meant to fix.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for robust change‑management controls (SOC 2 CC6.1) that require testing, approval, and documented evidence before production deployment.
- Highlights the importance of continuous control monitoring (SOC 2 CC7.1) to detect unintended side‑effects of patches and to capture temporary risk‑acceptance decisions.
- Aligns with Verisq’s Control Mapping capability, which automatically ties configuration changes to audit‑ready evidence in the Trust Center.
Who Is Affected — Any organization that builds or runs Windows desktop clients using the Windows Presentation Foundation (WPF) framework, spanning finance, healthcare, manufacturing, and SaaS vendors.
Recommended Actions
- Deploy the update first in a staging environment; validate printing/PDF workflows before production rollout.
- If a temporary workaround is required, document the risk acceptance, enable the AppContext switch, and set an expiration date.
- Map the change‑management and system‑operations steps to SOC 2 controls, and capture evidence through continuous monitoring tools.
- Monitor for any exploitation attempts that could leverage the disabled protection.
Source: BleepingComputer
Technical Notes
- Affected platforms: Windows 10, Windows 11, Windows Server 2012‑2025.
- Failure mode:
System.IO.FileFormatExceptiontriggered by specific font handling during print/PDF generation. - Workaround: Enable
Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtectionvia AppContext switch, which disables the August‑2026 protection and may expose the system to known font‑related vulnerabilities.
Source: Microsoft Windows Release Health Alert