logo

CVE-2026-40372: Critical ASP.NET Core Flaw May Let Attackers Gain SYSTEM Privileges

ID: 1e72200b-c473-5daf-a5e4-d9f893b69f14

STIX ID: report--1e72200b-c473-5daf-a5e4-d9f893b69f14

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-30

Author: SOC Prime Team

...
...

Microsoft patched CVE-2026-40372, a critical ASP.NET Core Data Protection flaw (CVSS 9.1) present in Microsoft.AspNetCore.DataProtection 10.0.0–10.0.6 that can let attackers forge authentication material (cookies, antiforgery tokens, OpenID state) and potentially escalate to SYSTEM on non-Windows hosts if the vulnerable NuGet is loaded at runtime; mitigation requires upgrading to 10.0.7, redeploying affected apps, and rotating the Data Protection key ring to invalidate tokens issued during the vulnerable window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.