Patch tracker / Products / ASP.NET Core 9.0

ASP.NET Core 9.0: vulnerabilities and security updates

Every CVE affecting ASP.NET Core 9.0 and the Microsoft update (KB) that fixes it, ranked by real-world risk. Actively exploited (CISA KEV) first, then EPSS exploit probability, on top of CVSS severity.

CVEs
2
Updates (KBs)
3
Actively exploited (KEV)
0
Critical Severity
0

CVEs affecting ASP.NET Core 9.0

CVESeverityCVSSEPSSStatus
CVE-2026-26130High7.52.8%-
CVE-2025-24070High7.01.0%-

Updates (KBs) for ASP.NET Core 9.0

UpdateReleasedSeverityCVSSEPSSCVEsStatus
KB50812772026-03-10High7.52.8%1-
KB50542292025-03-11High7.01.0%1-
KB50542302025-03-11High7.01.0%1-

Ranked across all products on the Microsoft patch tracker and the CVE and vulnerability management reference. Browse every product: product index.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.