Skip to main content
See every side of every news story
Published loading...Updated

Microsoft Issues Emergency Update for macOS and Linux ASP.NET Threat

Microsoft said attackers could forge authentication cookies through a cryptographic flaw, and warned that 10.0.0 through 10.0.6 are affected.

  • On Tuesday, Microsoft senior program manager Rahul Bhandari warned customers using ASP.NET Core Data Protection to update to 10.0.7, fixing CVE-2026-40372 that allows unauthenticated attackers to gain SYSTEM privileges.
  • Microsoft discovered the flaw following user reports of decryption failures after this month's Patch Tuesday, affecting NuGet packages 10.0.0 through 10.0.6 where HMAC validation tags are computed over incorrect bytes.
  • Unauthenticated attackers can exploit the vulnerability to decrypt protected payloads in cookies, antiforgery tokens, and OIDC state; Microsoft warned attackers may have induced applications to issue legitimately-signed tokens to themselves.
  • Devices remain vulnerable even after upgrading to 10.0.7 if authentication credentials created by a threat actor were not purged, as tokens remain valid unless the DataProtection key ring is rotated.
  • This incident follows a Kestrel web server bug fixed in October; security teams must ensure immediate redeployment to resolve the validation routine and prevent exploitation of cryptographic APIs.
Insights by Ground AI
Podcasts & Opinions

11 Articles

A few days ago, Microsoft released emergency patches for Windows Server, and now another out-of-band update is available. This time, it's an emergency patch for .NET that addresses a critical vulnerability identified as CVE-2026-40372. According to the IT security news portal Bleeping Computer, hackers can exploit this vulnerability to gain full access to the system via forged authentication cookies. The new version of .NET is designated 10.0.7 …

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news on Wednesday, April 22, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal