Story perspectives
Microsoft Issues Urgent Patch for Critical ASP.NET Core Vulnerability
4/23/2026
1 of 1
Story summary
- Microsoft issued an emergency patch for ASP.NET Core to fix CVE-2026-40372, a critical vulnerability that lets attackers gain SYSTEM privileges on Linux or macOS apps.
- The flaw stems from improper verification of cryptographic signatures in Microsoft.AspNetCore.DataProtection 10.0.0–10.0.6 and has a CVSS score of 9.1.
- Even after updating to 10.0.7, forged credentials may remain valid unless the DataProtection key ring is rotated.
- The vulnerability was discovered by an anonymous researcher.
