CyberICT

CVE-2026-40372

Microsoft · Published April 21, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

ASP.NET Core Elevation of Privilege Vulnerability. Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Affected Products

  • ASP.NET Core 10.0
  • Microsoft Visual Studio 2026 version 18.5

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C