Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
ID: c4612762-320f-597b-a530-07aec43df5a8
STIX ID: report--c4612762-320f-597b-a530-07aec43df5a8
Feed Name: The Hacker News
Threat Score
Microsoft disclosed CVE-2026-40372, a high-severity (CVSS 9.1) vulnerability in Microsoft.AspNetCore.DataProtection (NuGet 10.0.0–10.0.6) where an HMAC validation regression allowed forged payloads to pass authenticity checks, potentially enabling privilege escalation to SYSTEM on non-Windows hosts. Microsoft released fixes in ASP.NET Core 10.0.7 and warned that previously issued tokens remain valid unless the DataProtection key ring is rotated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
