Skip to content
Microsoft Issues Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability

Microsoft Issues Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability

Gbhackers April 22, 2026

Microsoft has issued an emergency out-of-band security update to address a severe vulnerability within the .NET framework.

The critical release of .NET 10.0.7 patches an Elevation of Privilege flaw that inadvertently surfaced after a recent routine system update.

Out-of-band patches bypass normal release schedules and indicate a pressing threat, meaning organizations relying on ASP.NET Core Data Protection must take immediate action to secure their infrastructure.

The vulnerability, officially tracked as CVE-2026-40372, originated from a software regression introduced during the .NET 10.0.6 Patch Tuesday rollout.

Shortly after that release, software engineers began reporting unexpected decryption failures across various applications.

While investigating these decryption errors on GitHub, Microsoft security researchers uncovered that the underlying bug was not just a functional glitch, but a severe security loophole.

The root cause of the flaw lies with Microsoft.AspNetCore.DataProtection NuGet package. In the affected builds, the managed authenticated encryptor failed to process its Hash-based Message Authentication Code (HMAC) correctly.

The encryptor calculated the validation tag using the wrong payload bytes and then discarded the resulting hash.

This cryptographic failure compromises data integrity, potentially allowing an attacker to manipulate payloads and elevate their system privileges without triggering authentication alarms.

This vulnerability directly threatens any application that uses ASP.NET Core Data Protection to secure sensitive data . Security teams should audit their environments immediately to identify exposed assets.

Fixing this vulnerability requires more than simply installing a system update on a server.

Development teams must manually update their project dependencies and redeploy their software to ensure complete protection against potential privilege escalation attacks .

Developers encountering stability issues or unexpected behaviors during the patching process are encouraged to report anomalies through the .NET release feedback repository.

Maintaining active communication with Microsoft’s engineering team will help ensure the stability of future cryptographic updates.

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Mozilla has released Firefox 150 to patch 41 security vulnerabilities, including multiple high-severity flaws that…

Malicious Google Ads are increasingly being used to steal cryptocurrency by draining wallets and harvesting…

Infrastructure intelligence firm Infrawatch has exposed a globally distributed SIM Farm-as-a-Service ecosystem powered by a…

A coordinated malware operation is abusing fake GitHub repositories to distribute a LuaJIT-based loader, SmartLoader,…

Cybercriminals are turning French freelancer fintech accounts into high-speed money laundering channels, moving stolen funds…

Hackers have deployed a new destructive malware, dubbed Lotus Wiper , in a targeted cyberattack against energy

Extracted Entities

Attack Types (1)

Campaigns (1)

Industries (1)

Malware (1)

Platforms (1)