Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40372

48
FAUCET Score

CVE-2026-40372 is a critical vulnerability in ASP.NET Core stemming from improper verification of cryptographic signatures, which enables unauthorized attackers to escalate privileges over network connections. The flaw allows remote exploitation without authentication or user interaction, making it a high-risk threat to affected systems. The vulnerability carries a CVSS score of 9.1 (Critical) with network-based attack vectors and low complexity requirements. It poses significant confidentiality and integrity risks, potentially allowing attackers to gain unauthorized elevated access to systems. The FAUCET Risk Score of 53.0/100 reflects moderate but meaningful operational risk. Currently, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The extremely low EPSS score of 0.000390000 indicates minimal probability of exploitation, and community attention appears limited at present. However, the critical CVSS rating warrants prompt patching and monitoring despite current low exploitation activity.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.0.0, < 10.0.7CPE matchmatch criteria
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
11.21%
Probability of exploitation in next 30 days
EPSS Percentile
95.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1120 is in the 91st percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

microsoftpatch availablevia msrc
Product: ASP.NET Core 10.0Fixed in: 10.0.7
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2026 version 18.5Fixed in: 18.5.2
View patch
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.DataProtectionFixed in: 10.0.7
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

nugetGHSA-9mv3-2cwr-p262critical

Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege

Apr 23, 2026
microsoft2026-Apr/CVE-2026-40372Important

ASP.NET Core Elevation of Privilege Vulnerability

Apr 14, 2026

References

access.redhat.com / security/cve/CVE-2026-40372
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-40372.json
msrc.microsoft.com / update-guide/vulnerability/CVE-2026-40372
Vendor Advisory