CVE-2025-26682
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-26682 is a denial-of-service vulnerability affecting ASP.NET Core. The issue permits an attacker to exhaust resources without limitation or throttling, leading to a network service disruption. This vulnerability can be exploited remotely, making it a significant security concern for organizations using ASP.NET Core applications. By consuming resources beyond the capacity of the system, an attacker can cause the application to become unresponsive or unavailable, resulting in a denial-of-service condition. It is essential for users to update their ASP.NET Core installations to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.