logo

Microsoft releases emergency patches for critical ASP.NET flaw

ID: c6d3df2d-7256-5354-b702-264a5d23743a

STIX ID: report--c6d3df2d-7256-5354-b702-264a5d23743a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Sergiu Gatlan

...
...

Microsoft released an out-of-band patch for a critical ASP.NET Core Data Protection vulnerability (CVE-2026-40372) in Microsoft.AspNetCore.DataProtection 10.0.0–10.0.6 that can allow attackers to forge authentication cookies and obtain SYSTEM-level privileges; organizations are urged to update to 10.0.7 and redeploy, and to rotate DataProtection key rings to mitigate forged-but-still-valid tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.