Critical Runtime Fix for .NET SDK Addresses CVE-2026-40372

Critical Runtime Fix for .NET SDK Addresses CVE-2026-40372

First seen 11 May 2026, 09:04 UTC Linuxsecurity 90% similarity 72.0

Article Content

Browse articles
ThreatCluster

.NET SDK 10.0.107 and Runtime 10.0.7 updates were released to address CVE-2026-40372, a significant vulnerability affecting Fedora 42 and 43. The vulnerability, published on April 21, 2026, could potentially allow unauthorized access or execution of malicious code. Users of Fedora 42 and 43 are urged to upgrade to the latest versions to mitigate risks associated with this CVE. The updates were made available on May 10 and May 11, respectively. The updates can be installed using the 'dnf' package manager. This situation highlights the importance of timely patching in maintaining system security. The vulnerability affects cross-platform applications developed using .NET, which is widely used in various environments.

Key Points: • CVE-2026-40372 affects .NET SDK and Runtime, posing a significant security risk. • Fedora 42 and 43 users must upgrade to .NET SDK 10.0.107 and Runtime 10.0.7 to mitigate this threat. • The vulnerability was published on April 21, 2026, and updates were released on May 10 and 11.

ThreatCluster AI

Timeline

2026-04-21
CVE-2026-40372 published
A critical vulnerability in the .NET SDK was disclosed, affecting multiple versions.
Linuxsecurity
2026-05-01
Updates released for .NET SDK
Fedora announced updates to .NET SDK 10.0.107 and Runtime 10.0.7 to fix CVE-2026-40372.
Linuxsecurity
2026-05-10
Fedora 42 update issued
Fedora 42 received an update to address the critical .NET vulnerability with SDK 10.0.107.
Linuxsecurity
2026-05-11
Fedora 43 update issued
Fedora 43 received an update to .NET SDK 10.0.107 and Runtime 10.0.7 to fix CVE-2026-40372.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story