CybersecuritySoftware

Microsoft Patches Critical ASP.NET Core Vulnerability Rated Among Most Severe in Company History

Microsoft has resolved what sources describe as one of its highest-rated security vulnerabilities affecting ASP.NET Core. The critical HTTP request smuggling bug could allow attackers to bypass security controls and access sensitive information. Security updates are now available for affected .NET and Visual Studio versions.

Critical Security Flaw Addressed

Microsoft has reportedly fixed what the company describes as one of its “highest ever” rated security vulnerabilities affecting its ASP.NET Core platform, according to recent security advisories. The critical flaw, tracked as CVE-2025-55315, received a severity score of 9.9 out of 10 and affected the Kestrel web server component.