CVE-2026-40372 ASP.NET Core Elevation of Privilege Vulnerability
Published April 22, 2026
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Published April 22, 2026
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Published April 22, 2026
Acknowledgement added. This is an informational change only.
Published April 22, 2026
Information published.
Published April 22, 2026
Information published.
Published April 22, 2026
Added Security Only packages to Windows Server 2012 security updates. This is an informational change only.
Published April 22, 2026
Added acknowledgements. This is an informational change only.
Published April 19, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Published April 19, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Published April 19, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Published April 19, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.