CVE-2026-40372Patch(microsoft / asp.net_core)

CRITICALCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 52 mentions and remains active

Immediate actions

  • Patch microsoft asp.net_core systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • asp.net_core

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 114 mentions across 14 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 88 signals
  • Technical details provided in 93 signals
  • Disclosure: 19 classified signals
  • General: 8 classified signals
  • Peaked 12d ago at 52 mentions (2026-04-22); latest day: 4
  • 114 total mentions across 14 days

Affected systems

Vendors
Products
asp.net_core

Deep dive

Activity timeline114 mentions / 14d
013263952Mentions · 2026-04-21: 7Mentions · 2026-04-22: 52Mentions · 2026-04-23: 21Mentions · 2026-04-24: 7Mentions · 2026-04-25: 5Mentions · 2026-04-26: 3Mentions · 2026-04-27: 4Mentions · 2026-04-28: 1Mentions · 2026-04-29: 2Mentions · 2026-04-30: 1Mentions · 2026-05-22: 2Mentions · 2026-05-27: 2Mentions · 2026-06-16: 3Mentions · 2026-06-19: 4PoC Mentioned / Linked · 2026-06-16: 1Exploit Tool / Code · 2026-06-16: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-05-27: 1Patch / Workaround · 2026-04-21: 4Patch / Workaround · 2026-04-22: 46Patch / Workaround · 2026-04-23: 18Patch / Workaround · 2026-04-24: 6Patch / Workaround · 2026-04-25: 4Patch / Workaround · 2026-04-26: 3Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-29: 2Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-06-19: 1Technical Details · 2026-04-21: 4Technical Details · 2026-04-22: 48Technical Details · 2026-04-23: 17Technical Details · 2026-04-24: 4Technical Details · 2026-04-25: 4Technical Details · 2026-04-26: 2Technical Details · 2026-04-27: 4Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-22: 2Technical Details · 2026-06-16: 3Technical Details · 2026-06-19: 204-2104-2204-2304-2404-2504-2604-2704-2804-2904-3005-2205-2706-1606-19
Signal classification5 categories
Patch
8271.9%
Disclosure
1916.7%
General
87.0%
Active Exploitation
43.5%
PoC
10.9%
Referenced assets78 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-217
General3Patch4
2026-04-2252
Active Exploitation1Disclosure7General2Patch42
2026-04-2321
Active Exploitation1Disclosure2General1Patch17
2026-04-247
Disclosure1Patch6
2026-04-255
Disclosure1Patch4
2026-04-263
Patch3
2026-04-274
Active Exploitation1Disclosure2Patch1
2026-04-281
Patch1
2026-04-292
Patch2
2026-04-301
Disclosure1
2026-05-222
General1Patch1
2026-05-272
Active Exploitation1General1
2026-06-163
Disclosure2PoC1
2026-06-194
Disclosure3Patch1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    ⚠️ Microsoft patched CVE-2026-40372 (CVSS 9.1) in ASP .NET Core enabling SYSTEM-level escalation. A crypto flaw let attackers forge payloads and decrypt auth data in apps using vulnerable Data Protection on Linux/macOS. 🔗 Read → https://thehackernews.com/2026/04/microsoft-patches-critical-aspnet-core.html

    Post summary

    Microsoft has issued a patch for the critical CVE-2026-40372 in ASP.NET Core, which allowed attackers to cause system‑level escalation through a cryptographic flaw in Data Protection on Linux and macOS.

    023155913.1K
    1.8M followersView on X
  • .NET Foundation@dotnetfdn
    Patch

    📣.NET 10.0.7 Out-of-Band Security Update - .NET Blog Microsoft released .NET 10.0.7 as an out-of-band security update to address CVE-2026-40372. https://hubs.li/Q04dbWjB0 #dotnet https://t.co/TiiBeFU05l

    Post summary

    Microsoft issued .NET 10.0.7 as a security update for CVE‑2026‑40372, with no PoC, exploit code, or active exploitation details provided.

    0202221.5K
    60.4K followersView on X
  • 情報の灯台@joho_no_todai
    Patch

    ASP. NET Coreで緊急のOOBパッチが公開された。 CVE-2026-40372、CVSS 9.1の権限昇格。 発端は先週14日のパッチチューズデーで配られた10.0.6そのもの。 復号が失敗するとの報告を追って調査した結果、定例パッチ自身が認証Cookieを偽造できる穴を開けていたことが判明した。 パッチを当てる文化は、当てたパッチを再検証する文化とセットでないと成立しない。 https://joho-todai.com/asp-net-core-patch-vulnerability-emergency-oob/

    Post summary

    The post announces an emergency OOB patch for ASP.NET Core (CVE-2026-40372) that fixes a privilege‑escalation flaw involving forged authentication cookies; no exploit or PoC is reported.

    1301411.5K
    10.7K followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    Microsoft Patches Critical http://ASP.NET Core CVE-2026-40372 Privilege Escalation Bug https://thehackernews.com/2026/04/microsoft-patches-critical-aspnet-core.html

    Post summary

    Microsoft has released a critical patch for CVE‑2026‑40372, a privilege escalation vulnerability in ASP.NET Core, as reported by The Hacker News.

    0301232.2K
    158.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Microsoft releases .NET 10.0.7 to fix CVE-2026-40372, a critical 9.1 severity flaw in http://ASP.NET Core Data Protection. Update now to prevent privilege escalation. #DotNet #Microsoft #InfoSec #CVE #SoftwareUpdate #ASPNetCore #SysAdmin https://securityexpress.info/dotnet-10-cve-2026-40372-security-update-privilege-escalation/ https://t.co/GIJXMMjPJv

    Post summary

    Microsoft has released .NET 10.0.7 to address the critical CVE‑2026‑40372 flaw, which could lead to privilege escalation via ASP.NET Core Data Protection.

    110671.1K
    12.5K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    🛑 Microsoft a publié un patch pour une vulnérabilité dans ASP .NET CVE-2026-40372 - Faille de sécurité critique La nouvelle version remplace celle publiée il y a quelques jours lors du Patch Tuesday. Plus d'infos 👇 - https://www.it-connect.fr/microsoft-a-publie-un-patch-pour-une-faille-critique-dans-asp-net-cve-2026-40372/ #infosec #cybersecurite #windows https://t.co/nbUVXeDJFT

    Post summary

    Microsoft released a patch for the critical ASP.NET vulnerability CVE‑2026‑40372.

    00070649
    11.5K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na kritickou zranitelnost v ASP.​NET Core, CVE-2026-40372. Zranitelnost s hodnocením CVSS 9.1 umožňuje vzdálenou eskalaci oprávnění až na úroveň SYSTEM v důsledku nesprávné validace kryptografického podpisu v komponentě Microsoft.AspNetCore.DataProtection. Problém se týká aplikací využívajících zranitelné verze této komponenty distribuované přes NuGet v rozsahu verzí 10.0.0 až 10.0.6. Útočník může při splnění podmínek zneužití podvrhnout autentizační tokeny, obejít mechanismy ověřování, získat přístup k citlivým datům a zajistit si perzistentní přístup k systému, přičemž v případě již proběhlého zneužití může přístup přetrvat i po aplikaci záplaty bez dodatečných nápravných kroků. 📌Doporučujeme neprodleně aktualizovat na verzi Microsoft.AspNetCore.DataProtection 10.0.7 nebo vyšší a provést rotaci Data Protection Key Ring za účelem zneplatnění dříve vydaných kryptografických tokenů.

    Post summary

    CVE‑2026‑40372 is a critical remote privilege escalation flaw in ASP.NET Core’s Data Protection component, affecting versions 10.0.0‑10.0.6; users should upgrade to 10.0.7+ and rotate keys.

    03030521
    4.2K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    🚨 Microsoft ASP .NET Core hit by critical privilege escalation flaw (CVE-2026-40372) Auth cookie forgery → bypass validation → SYSTEM-level access 💡 Lesson: Cryptographic implementation bugs can completely break authentication — security ≠ just encryption ⚠️ Action: Update to ASP .NET Core 10.0.7 immediately + rotate DataProtection keys to invalidate forged tokens https://thehackernews.com/2026/04/microsoft-patches-critical-aspnet-core.html

    Post summary

    The tweet announces a critical privilege escalation vulnerability (CVE-2026-40372) in ASP.NET Core that allows auth cookie forgery to gain SYSTEM access, and recommends immediately updating to v10.0.7 and rotating DataProtection keys.

    10041514
    16.1K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Microsoft releases emergency patches for a critical http://ASP.NET Core flaw (CVE-2026-40372) allowing forged auth cookies to escalate to SYSTEM privileges. Update to 10.0.7 and rotate DataProtection keys. #ASPNetCore #MicrosoftPatch #USA https://ift.tt/68eJyzP

    Post summary

    Microsoft released emergency patches for CVE-2026-40372, which permits forged auth cookies to achieve SYSTEM privileges; users are advised to update to .NET Core 10.0.7 and rotate DataProtection keys.

    10031172
    4.4K followersView on X
  • XHack@xhackio
    Patch

    🛡️ The Critical http://ASP.NET Core Flaw: CVE-2026-40372 Explained Microsoft just patched a critical privilege escalation bug in http://ASP.NET Core, tracked as CVE-2026-40372 with a CVSS score of 9.1. This out-of-band update highlights a vulnerability that could allow an attacker to gain elevated privileges on a system. For bug hunters, this is a prime example of why understanding application frameworks is key. Flaws in core components like http://ASP.NET can have widespread impact. The writeup would likely detail how improper access control or request handling could be exploited. It's a reminder to always test authorization boundaries and assume nothing is secure by default. What's your process for testing privilege escalation in modern web frameworks? https://thehackernews.com/2026/04/microsoft-patches-critical-aspnet-core.html #bugbounty #infosec #cybersecurity

    Post summary

    Microsoft released a patch for the high‑CVSS privilege escalation flaw CVE‑2026‑40372 in ASP.NET Core; the post confirms the patch and vulnerability details but does not report a PoC or active exploitation.

    01030144
    33 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical http://ASP.NET Core vuln patched (CVE-2026-40372) Attackers could forge authentication tokens → gain SYSTEM privileges Who's affected: - Your application uses Microsoft.AspNetCore.DataProtection 10.0.0-10.0.6. - Your application runs on Linux, macOS, or another non-Windows OS. 👉 Update to 10.0.7 + rotate key ring now

    Post summary

    Microsoft ASP.NET Core CVE-2026-40372 is a critical flaw allowing attackers to forge authentication tokens and gain SYSTEM privileges; the fix is to update to version 10.0.7 and rotate the key ring.

    00040193
    41 followersView on X
  • INSA- የኢንፎርሜሽን መረብ ደህንነት አስተዳደር@INSAEthio
    Patch

    🚨 Microsoft released emergency patches for a critical http://ASP.NET flaw (CVE-2026-40372) enabling SYSTEM-level access via forged authentication cookies. 🔐 Update to v10.0.7, redeploy, and rotate keys immediately. #CyberSecurity #INSA #Microsoft #ASPNet https://t.co/lzVcgWIqdm

    Post summary

    Microsoft has issued emergency patches for CVE‑2026‑40372, recommending update to v10.0.7, redeployment, and key rotation to mitigate a SYSTEM‑level access vulnerability via forged authentication cookies.

    01020191
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-40372 can forge http://ASP.NET Core authentication cookies to escalate to SYSTEM privileges and move laterally across networks. Runtime segmentation helps contain such post-compromise activity by limiting blast radius when authentication mechanisms fail. #ZeroTrust #Vulnerability 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/microsoft-releases-emergency-security-updates-for-critical-aspnet-flaw-cve-2026-40372

    Post summary

    Attackers are actively exploiting CVE-2026-40372 by forging ASP.NET Core authentication cookies to achieve SYSTEM-level privileges and move laterally, while runtime segmentation is suggested as a containment measure.

    1002098
    1.9K followersView on X
  • AI実務メモ|毎朝AIツール仕分け@digest_tech_jp
    Patch

    🔥 http://ASP.NET Coreに緊急パッチ——CVSS 9.1の権限昇格バグを今すぐ適用を ─── 🌍 4/23(木)テックニュース ─── 🔒 セキュリティ ➤ Microsoft、http://ASP.NET Core CVE-2026-40372(CVSS 9.1)の緊急パッチを帯域外リリース  ・権限昇格の脆弱性。対象システムは即時アップデート推奨 ➤ Firefox/Torユーザーに注意——IndexedDBのバグで全プライベートセッションを紐付け可能な安定識別子が発覚  ・Torブラウザ経由でも匿名性が破られる可能性。修正状況を要確認 ➤ Checkmarx KICSのDocker HubイメージとVS Code拡張機能にサプライチェーン攻撃——既存タグが悪意あるイメージで上書き ➤ npmパッケージを介して自己増殖するサプライチェーンワームを確認——開発者トークンを窃取 🤖 AI / LLM ➤ OpenAI、ChatGPT Images 2.0を正式リリース——日本語テキスト描写も大幅向上  ・「考えてから描く」設計で精度が向上。無料プランでも利用可能 ➤ Google Cloud Next 2026:第8世代TPU「8t(学習特化)」「8i(推論特化)」を発表  ・用途別に最適化した2チップ構成で前世代比大幅な性能・電力効率向上 ➤ OpenAI、ChatGPTにCodexベースの「Workspace Agents」を追加——Business/Enterprise向けにクラウド上で業務タスクを自律実行 ➤ Qwen3.6-27B公開——27Bの密なモデルでフラッグシップ級のコーディング性能を実現 ☁️ クラウド / インフラ ➤ Google Cloud Next 2026:大規模分散RDB「Spanner Omni」プレビュー公開——ローカルマシンにインストール可能に ➤ Google Cloud Next 2026:AIエージェント開発基盤「Gemini Enterprise Agent Platform」発表——ローコードの「Agent Studio」含む包括的プラットフォーム ➤ AWS Lambda durable functionsが16リージョンに拡大 🔧 開発ツール / DevOps ➤ GitHub CLIが擬似匿名テレメトリの収集を開始——デフォルトでオプトイン  ・無効化はhttp://github.com/cli/cli/telemetryで手順を確認 ➤ Ubuntu 26.04 LTS(Noble Numbat)が本日リリース——25.10からの主な変更点まとめ ➤ AWS DevOps AgentとGuardDutyを連携——深夜のアラートをAIが自律調査、翌朝には報告書が揃う フォローして毎朝テックニュースをチェック👉 @digest_tech_jp

    Post summary

    Microsoft issued an emergency patch for the high‑severity privilege escalation vulnerability CVE‑2026‑40372 in ASP.NET Core and advises users to update immediately. No active exploitation or PoC information is provided.

    10020172
    4 followersView on X
  • CiberBaur@BotBauR
    Patch

    Acaba de confirmarse: Microsoft ha parcheado una vulnerabilidad crítica en http://ASP.NET Core que podría permitir a un atacante escalar privilegios, con un puntaje CVSS de 9.1 sobre 10.0. Microsoft ha parcheado la vulnerabilidad CVE-2026-40372, que afecta a http://ASP.NET Core y podría permitir a un atacante escalar privilegios. La vulnerabilidad fue descubierta por un investigador anónimo y tiene un puntaje CVSS de 9.1 sobre 10.0. La vulnerabilidad se debe a una verificación incorrecta de criptografía y podría permitir a un atacante escalar privilegios en un sistema vulnerable. Es importante que los administradores de sistemas actualicen sus sistemas lo antes posible para evitar cualquier posible ataque. El parche ya está disponible y es importante que los usuarios lo apliquen lo antes posible. ¿Estás en riesgo? Revisa esto: actualiza tu sistema a la última versión de http://ASP.NET Core y asegúrate de que no estés utilizando una versión vulnerable. https://thehackernews.com/2026/04/microsoft-patches-critical-aspnet-core.html

    Post summary

    The post announces that Microsoft has released a patch for CVE‑2026‑40372 affecting ASP.NET Core, detailing the vulnerability type (cryptography check flaw leading to privilege escalation) and CVSS score, while emphasizing the need to apply the update promptly.

    0102063
    153 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Microsoft issues emergency out-of-band .NET 10.0.7 update to fix critical CVE-2026-40372 EoP flaw affecting Linux and macOS systems on .NET 10.0.6. https://threatcluster.io/cluster/microsoft-issues-urgent-net-update-to-address-critical-secur-55197298

    Post summary

    Microsoft has issued an emergency update for .NET 10.0.7 to fix the critical elevation‑of‑privilege flaw (CVE‑2026‑40372) affecting Linux and macOS systems.

    01011123
    160 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    .NET 10で重大(Critical)な脆弱性が定例外緊急修正。CVE-2026-40372はCVSSスコア9.1で、Microsoft.AspNetCore.DataProtectionライブラリにおける認証cookieが持続可能な脆弱性。主に非Windows環境で稼働するアプリに影響。更新のほか、キーローテも推奨。 https://securityonline.info/dotnet-10-authentication-bypass-cve-2026-40372-remediation/

    Post summary

    The post announces a critical CVE-2026-40372 in .NET 10’s DataProtection library, details the severity and type of the vulnerability, and confirms an emergency patch plus key‑rotation best practice has been released.

    000301.1K
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Microsoft's OOB update for .NET 10 (CVE-2026-40372) hits Linux/macOS users. Authentication is at risk. Stop the bypass and rotate your keys today. #DotNet #CyberSecurity #InfoSec #Microsoft #Linux #AuthBypass #CVE202640372 #WebDev https://securityonline.info/dotnet-10-authentication-bypass-cve-2026-40372-remediation/ https://t.co/sIdkHKi4FH

    Post summary

    Microsoft released an out‑of‑band update for .NET 10 to fix an authentication bypass (CVE‑2026‑40372) affecting Linux/macOS; users are urged to apply the patch and rotate credentials.

    00012373
    11.3K followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 4.21 ASP\.NET Core Elevation of Privilege Vulnerability CVE-2026-40372 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40372

    Post summary

    Microsoft announced CVE-2026-40372, an elevation‑of‑privilege vulnerability in ASP.NET Core, with no PoC, exploit, or patch details provided in the tweet.

    10100127
    85 followersView on X
  • Saudi ICT Shopper News | صحيفة سعودي شوبر@ssict
    Patch

    أبرز التفاصيل: ✅ ثغرة ASP Core CVE-2026-40372 تؤثر على إصدارات 10.0.0 إلى 10.0.6 بدرجة خطورة 9.1 ✅ التحقق الخاطئ من التوقيع التشفيري يسمح بتصعيد الامتيازات على الأنظمة غير Windows ✅ يجب على المستخدمين التحديث إلى 10.0.7 وتدوير مفاتيح DataProtection لتخفيف الخطر بالكامل Key Highlights: 🔹 CVE-2026-40372 affects ASP Core versions 10.0.0 through 10.0.6 with 9.1 severity rating 🔹 Faulty cryptographic signature verification allows privilege escalation on non-Windows systems 🔹 Users must update to 10.0.7 and rotate DataProtection key rings to fully remediate risk

    Post summary

    CVE-2026-40372 affects ASP Core 10.0.0‑10.0.6 via faulty cryptographic signature verification, enabling privilege escalation on non‑Windows systems; update to 10.0.7 and rotate DataProtection key rings to fully mitigate the vulnerability.

    1001068
    21.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftasp.net_core---

Explore more