情報の灯台[verified]@joho_no_todaiPatch
The post announces an emergency OOB patch for ASP.NET Core (CVE-2026-40372) that fixes a privilege‑escalation flaw involving forged authentication cookies; no exploit or PoC is reported.
Nicolas Krassas[verified]@DinosnPatch
Microsoft has released a critical patch for CVE‑2026‑40372, a privilege escalation vulnerability in ASP.NET Core, as reported by The Hacker News.
GovCERT.CZ[verified]@GOVCERT_CZDisclosure
CVE‑2026‑40372 is a critical remote privilege escalation flaw in ASP.NET Core’s Data Protection component, affecting versions 10.0.0‑10.0.6; users should upgrade to 10.0.7+ and rotate keys.
Vivek | Cybersecurity[verified]@VivekIntelPatch
The tweet announces a critical privilege escalation vulnerability (CVE-2026-40372) in ASP.NET Core that allows auth cookie forgery to gain SYSTEM access, and recommends immediately updating to v10.0.7 and rotating DataProtection keys.
Cybersecurity News Everyday[verified]@TweetThreatNewsPatch
Microsoft released emergency patches for CVE-2026-40372, which permits forged auth cookies to achieve SYSTEM privileges; users are advised to update to .NET Core 10.0.7 and rotate DataProtection keys.
Upwind Security MDR[verified]@UpwindMDRPatch
Microsoft ASP.NET Core CVE-2026-40372 is a critical flaw allowing attackers to forge authentication tokens and gain SYSTEM privileges; the fix is to update to version 10.0.7 and rotate the key ring.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
Attackers are actively exploiting CVE-2026-40372 by forging ASP.NET Core authentication cookies to achieve SYSTEM-level privileges and move laterally, while runtime segmentation is suggested as a containment measure.
CiberBaur[verified]@BotBauRPatch
The post announces that Microsoft has released a patch for CVE‑2026‑40372 affecting ASP.NET Core, detailing the vulnerability type (cryptography check flaw leading to privilege escalation) and CVSS score, while emphasizing the need to apply the update promptly.