CyberICT

CVE-2026-40411

Microsoft · Published May 21, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Azure Virtual Network Gateway Remote Code Execution Vulnerability. Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

Affected Products

  • Azure Virtual Network Gateway

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C