CVE-2026-40411Disclosure(microsoft / azure_virtual_network_gateway)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft azure_virtual_network_gateway systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_virtual_network_gateway

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
azure_virtual_network_gateway

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-23: 1Mentions · 2026-05-25: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 105-2305-25
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-231
Disclosure1
2026-05-251
Active Exploitation1
Full discourse2 posts
  • NerdieNews@NewsNerdie
    Active Exploitation

    ⚠️ CVE-2026-40411 in Azure Virtual Network Gateway is being exploited, allowing attackers to execute remote code. This critical vulnerability demands immediate attention. Patch now to prevent a full compromise. #NerdieNews #CyberSecurity #Vulnerability https://t.co/I5xauw5hF3

    Post summary

    The post warns that CVE‑2026‑40411 is currently exploited for remote code execution in Azure Virtual Network Gateway and urges immediate patching to prevent full compromise.

    0000063
    64 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40411 Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-40411

    Post summary

    CVE‑2026‑40411 is disclosed as an RCE flaw in Azure Virtual Network Gateway; no PoC, exploit code, active exploitation, or patch information is provided.

    00000170
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_virtual_network_gateway---

Explore more