Drooid Logo
Back to today’s briefing

Story perspectives

Microsoft Issues Urgent Patch for Critical ASP.NET Core Vulnerability

4/23/2026

37 8 Full Breakdown

1 of 1

Story summary
  • Microsoft issued an emergency patch for ASP.NET Core to fix CVE-2026-40372, a critical vulnerability that lets attackers gain SYSTEM privileges on Linux or macOS apps.
  • The flaw stems from improper verification of cryptographic signatures in Microsoft.AspNetCore.DataProtection 10.0.0–10.0.6 and has a CVSS score of 9.1.
  • Even after updating to 10.0.7, forged credentials may remain valid unless the DataProtection key ring is rotated.
  • The vulnerability was discovered by an anonymous researcher.