Emergency .NET Update: Critical Data Protection Flaw Allows Authentication Forgery
ID: d384edf9-cc78-5bb6-b832-854455f6a0a5
STIX ID: report--d384edf9-cc78-5bb6-b832-854455f6a0a5
Feed Name: securityonline.info
Threat Score
Microsoft issued an out-of-band patch (10.0.7) for CVE-2026-40372, a critical vulnerability in Microsoft.AspNetCore.DataProtection used by ASP.NET Core on .NET 10 (non-Windows) that allows attackers to forge authentication cookies, gain privileged access, and potentially decrypt protected data; recommended remediation is immediate upgrade, DataProtection key-ring rotation to invalidate tokens, and auditing of logs and long-lived artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
