cbcvebase.
CVE-2026-40372
published 2026-04-21

CVE-2026-40372: Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftasp.net_core>= 10.0.0 < 10.0.710.0.7
microsoftasp.net_core_10.0>= 10.0 < 10.0.710.0.7
microsoftmicrosoft_visual_studio_2026_version_18.5>= 18.5.0 < 18.5.218.5.2
ubuntudotnet10

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ghsa9.1CRITICAL