CVE-2025-7326: Microsoft ASP.NET Core 6.0

High severity, CVSS 7.0. EPSS: 0.7% chance of exploitation in the next 30 days.

Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.

Affected products

  • Microsoft ASP.NET Core 6.0: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.linux-Arm: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.linux-ARM64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.linux-Musl-Arm: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.linux-Musl-ARM64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.linux-Musl-x64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.linux-x64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.osx-ARM64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.osx-x64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.win-Arm: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.win-ARM64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.win-x64: from 6.0.0
  • Microsoft Microsoft.aspnetcore.app.runtime.win-x86: from 6.0.0
  • Microsoft Microsoft.aspnetcore.identity: from 6.0.0

Published 2025-07-08. Last modified 2026-06-17.