logo

Emergency .NET Update: Critical Data Protection Flaw Allows Authentication Forgery

ID: d384edf9-cc78-5bb6-b832-854455f6a0a5

STIX ID: report--d384edf9-cc78-5bb6-b832-854455f6a0a5

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft issued an out-of-band patch (10.0.7) for CVE-2026-40372, a critical vulnerability in Microsoft.AspNetCore.DataProtection used by ASP.NET Core on .NET 10 (non-Windows) that allows attackers to forge authentication cookies, gain privileged access, and potentially decrypt protected data; recommended remediation is immediate upgrade, DataProtection key-ring rotation to invalidate tokens, and auditing of logs and long-lived artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.