CVE-2026-40306: Dnnsoftware DotNetNuke
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue.
Affected products
- Dnnsoftware DotNetNuke: from 10.0.0, before 10.2.2 (fixed in 10.2.2)
Published 2026-04-17. Last modified 2026-06-17.