Skip to content

CVE-2026-40372

CVE

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
April 22, 2026
Last Seen
May 11, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

CrowdStrike disclosed a critical vulnerability (CVE-2026-40050) in its LogScale product, allowing unauthenticated attackers to exploit a path traversal flaw to access sensitive files. This vulnerability affects self-hosted LogScale customers, while SaaS users have been mitigated. Additionally, Tenab...

On April 21, 2026, Microsoft released an emergency out-of-band update, .NET 10.0.7, to address a critical privilege escalation vulnerability tracked as CVE-2026-40372. This flaw, found in the ASP.NET Core Data Protection cryptographic APIs, allows unauthenticated attackers to forge authentication co...

.NET SDK 10.0.107 and Runtime 10.0.7 updates were released to address CVE-2026-40372, a significant vulnerability affecting Fedora 42 and 43. The vulnerability, published on April 21, 2026, could potentially allow unauthorized access or execution of malicious code. Users of Fedora 42 and 43 are urge...

Public Exploits

Checking GitHub for proof-of-concept code…