Home › Intelligence › Brief
BREACH BRIEF🟠 High Advisory

Microsoft August 2026 .NET Update Breaks Printing & PDF Export in WPF Apps

A Microsoft .NET Framework cumulative update caused WPF applications to fail when printing or exporting PDFs, prompting a temporary workaround that disables new font protections. The incident underscores the need for SOC 2‑aligned change‑management and continuous monitoring.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Microsoft August 2026 .NET Update Breaks Printing & PDF Export in WPF Apps

What Happened — A cumulative .NET Framework update released in August 2026 caused WPF‑based applications to throw System.IO.FileFormatException when printing or generating PDF/XPS files that use certain fonts (e.g., Calibri). Microsoft issued a temporary workaround that disables a new font‑handling protection, which itself re‑exposes the system to the very vulnerabilities the update was meant to fix.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for robust change‑management controls (SOC 2 CC6.1) that require testing, approval, and documented evidence before production deployment.
  • Highlights the importance of continuous control monitoring (SOC 2 CC7.1) to detect unintended side‑effects of patches and to capture temporary risk‑acceptance decisions.
  • Aligns with Verisq’s Control Mapping capability, which automatically ties configuration changes to audit‑ready evidence in the Trust Center.

Who Is Affected — Any organization that builds or runs Windows desktop clients using the Windows Presentation Foundation (WPF) framework, spanning finance, healthcare, manufacturing, and SaaS vendors.

Recommended Actions

  • Deploy the update first in a staging environment; validate printing/PDF workflows before production rollout.
  • If a temporary workaround is required, document the risk acceptance, enable the AppContext switch, and set an expiration date.
  • Map the change‑management and system‑operations steps to SOC 2 controls, and capture evidence through continuous monitoring tools.
  • Monitor for any exploitation attempts that could leverage the disabled protection.

Source: BleepingComputer

Technical Notes

  • Affected platforms: Windows 10, Windows 11, Windows Server 2012‑2025.
  • Failure mode: System.IO.FileFormatException triggered by specific font handling during print/PDF generation.
  • Workaround: Enable Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection via AppContext switch, which disables the August‑2026 protection and may expose the system to known font‑related vulnerabilities.

Source: Microsoft Windows Release Health Alert

📰 Original Source
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-updates-break-printing-pdf-export-in-wpf-apps/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →