Skip to main content
Security

Microsoft Issues Emergency Patches for Critical ASP.NET Core Vulnerability

Microsoft Issues Emergency Patches for Critical ASP.NET Core Vulnerability Image: Primary
Microsoft has issued out-of-band security updates for a critical vulnerability in ASP.NET Core that could allow unauthenticated attackers to gain SYSTEM privileges by forging authentication cookies. The flaw, tracked as CVE-2026-40372, resides in the ASP.NET Core Data Protection cryptographic APIs. Microsoft said a regression in the Microsoft.AspNetCore.DataProtection NuGet packages for versions 10.0.0 through 10.0.6 causes the managed authenticated encryptor to compute its HMAC validation tag over the wrong bytes of the payload and discard the computed hash in some cases. The broken validation could allow an attacker to forge payloads that pass authenticity checks and decrypt previously-protected data in auth cookies, antiforgery tokens, TempData, and OIDC state. If an attacker authenticated as a privileged user during the vulnerable window, they could induce the application to issue legitimately-signed tokens to themselves. Those tokens remain valid after upgrading to version 10.0.7 unless the DataProtection key ring is rotated. Microsoft discovered the flaw after user reports that decryption was failing following the .NET 10.0.6 update released during this month's Patch Tuesday. Senior program manager Rahul Bhandari urged customers to update to version 10.0.7 and redeploy to fix the validation routine.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Google issues Chrome update for actively exploited V8 flaw

Google has released an emergency Chrome update for CVE-2026-85046, a high-severity type-confusion vulnerability in the browser's V8 JavaScript and WebAssembly engine, according to Cybersecurity News. The report says Google is awar...

Capital
Capital

Anthropic nears $15 billion revolver ahead of IPO filing

Anthropic is set to finalize an expansion of its revolving credit facility to $15 billion, according to people familiar with the matter cited by Bloomberg. Morgan Stanley is leading the process, with Goldman Sachs, JPMorgan Chase ...

Infrastructure
Infrastructure

Firmus commits $300 million for Australia-US cable capacity

Australian AI cloud firm Firmus will invest $300 million to secure up to 150Tbps of dedicated capacity for 25 years on SubCo's planned APX East submarine cable system. The 16-fiber-pair cable, first announced in January, is inten...

AI
AI

G42 explores majority US ownership to protect chip access

Abu Dhabi-based AI company G42 has held exploratory talks about potentially selling a majority stake to American companies, according to people familiar with the matter. The reported discussions are aimed at securing the company's...

Infrastructure
Infrastructure

Meta brings Kuna AI-optimized data center online

Meta's Kuna, Idaho, data center is now serving traffic, according to the company's data-center development vice president. The facility is Meta's second AI-optimized site to come online and represents an overall investment of $1.2...

Infrastructure Policy
Infrastructure Policy

Russia bans crypto mining in Moscow region through 2032

Russia's government has banned cryptocurrency mining and mining-pool participation in Moscow, the surrounding region and parts of Kursk through the end of 2032 under Government Decree No. 936. The measure is intended to reduce pre...