CVE-2026-39399
Attacker can execute code or overwrite files on NuGet Gallery by uploading a malicious package.
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A critical flaw in NuGet Gallery allows attackers to execute code or overwrite files by uploading a malicious package, posing a risk to stored content and the server itself.