CVE-2026-40372
Microsoft ASP.NET Core 10.0, Microsoft Visual Studio 2026 version 18.5, Red Hat Enterprise Linux 10
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
- CVSS
- 9.1
- EPSS
- 11.2% 95.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.22