CVE-2026-40372
Microsoft · Published April 21, 2026
9.1
CVSS v3.1
CRITICALPatch availableGet patch
Description
ASP.NET Core Elevation of Privilege Vulnerability. Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Affected Products
- ASP.NET Core 10.0
- Microsoft Visual Studio 2026 version 18.5
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C