CVE-2026-40411
Microsoft · Published May 21, 2026
9.9
CVSS v3.1
CRITICALPatch availableGet patch
Description
Azure Virtual Network Gateway Remote Code Execution Vulnerability. Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
Affected Products
- Azure Virtual Network Gateway
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C