PatchSiren cyber security CVE debrief
CVE-2026-40372 Microsoft CVE debrief
CVE-2026-40372 is a critical vulnerability in ASP.NET Core that allows an unauthorized attacker to elevate privileges over a network due to improper verification of cryptographic signatures. The vulnerability has a CVSS score of 9.1 and is considered critical. It was published on April 21, 2026, and last modified on June 27, 2026. The vendor, Microsoft, has provided a mitigation or vendor reference for this vulnerability. Users of ASP.NET Core should review the vendor advisory and take necessary actions to mitigate the vulnerability.
- Vendor
- Microsoft
- Product
- ASP.NET Core 10.0
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-07-15
Who should care
Users of ASP.NET Core, particularly those who have not updated to a patched version, should be aware of this critical vulnerability. An unauthorized attacker could exploit this vulnerability to elevate privileges over a network. Microsoft has provided guidance on mitigating this vulnerability.
Technical summary
The vulnerability is caused by improper verification of cryptographic signatures in ASP.NET Core. This allows an unauthorized attacker to elevate privileges over a network. The vulnerability has been assigned a CVSS score of 9.1 and is considered critical. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. The weakness associated with this vulnerability is CWE-347.
Defensive priority
High priority should be given to patching or mitigating this vulnerability, as it allows for privilege escalation over a network. Microsoft has provided a vendor advisory that should be reviewed and implemented.
Recommended defensive actions
- Review and apply the vendor advisory provided by Microsoft.
- Ensure that ASP.NET Core is updated to a patched version.
- Implement compensating controls, such as monitoring and exception tracking, if patching is not immediately feasible.
- Review defender inventory and perform necessary checks to identify potential vulnerabilities.
- Consider implementing additional security measures, such as network segmentation and access controls.
Evidence notes
The source item for this vulnerability is from the NVD, which provides detailed information about the vulnerability, including its CVSS score, CVSS vector, and weaknesses. The vendor, Microsoft, has provided a mitigation or vendor reference for this vulnerability. Additional references are provided by Red Hat.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40372 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40372
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40372 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40372
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40372
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-40372
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40372.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.