Neowin Microsoft Issues Emergency Patches for Critical ASP.NET Core Vulnerability
Article Content
- •Microsoft released .NET 10.0.7 to patch CVE-2026-40372, a critical privilege escalation vulnerability.
- •The flaw allows unauthenticated attackers to forge authentication cookies and gain SYSTEM privileges.
- •All non-Windows operating systems using .NET 10.0.6 are affected, necessitating immediate updates.
On April 21, 2026, Microsoft released an emergency out-of-band update, .NET 10.0.7, to address a critical privilege escalation vulnerability tracked as CVE-2026-40372. This flaw, found in the ASP.NET Core Data Protection cryptographic APIs, allows unauthenticated attackers to forge authentication cookies, potentially gaining SYSTEM privileges on affected devices. The vulnerability was discovered after users reported decryption failures following the installation of .NET 10.0.6 during Patch Tuesday. Microsoft has emphasized that all non-Windows operating systems using .NET 10.0.6 are impacted, and it is crucial for affected users to update to the latest version immediately. The flaw has a CVSS score of 9.1, indicating a severe risk of exploitation. Organizations are advised to rotate their DataProtection key rings to mitigate risks from previously issued tokens. This incident follows a previous critical vulnerability (CVE-2025-55315) patched in October 2025, highlighting ongoing security challenges in the ASP.NET framework.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track CVE-2010-3332 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…