CVE-2026-40372 is a critical vulnerability in ASP.NET Core stemming from improper verification of cryptographic signatures, which enables unauthorized attackers to escalate privileges over network connections. The flaw allows remote exploitation without authentication or user interaction, making it a high-risk threat to affected systems. The vulnerability carries a CVSS score of 9.1 (Critical) with network-based attack vectors and low complexity requirements. It poses significant confidentiality and integrity risks, potentially allowing attackers to gain unauthorized elevated access to systems. The FAUCET Risk Score of 53.0/100 reflects moderate but meaningful operational risk. Currently, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The extremely low EPSS score of 0.000390000 indicates minimal probability of exploitation, and community attention appears limited at present. However, the critical CVSS rating warrants prompt patching and monitoring despite current low exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.0.7CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.