Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability
ID: 58398090-9cf0-5298-9ebb-f8fe318b621c
STIX ID: report--58398090-9cf0-5298-9ebb-f8fe318b621c
Feed Name: cybersecurityNews.com
Microsoft released an emergency .NET 10.0.7 update on April 21, 2026 to remediate CVE-2026-40372 — a critical elevation-of-privilege vulnerability in the Microsoft.AspNetCore.DataProtection package (10.0.0–10.0.6). The managed encryptor could compute HMACs over incorrect payload bytes and discard the result, enabling integrity bypass of cookies, tokens, and other protected application state; organizations are urged to upgrade to 10.0.7, rebuild/redeploy applications, and verify runtime versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
