Microsoft patches critical ASP.NET Core data-protection flaw to curb cookie forgery

1 min read
Source: BleepingComputer
Microsoft patches critical ASP.NET Core data-protection flaw to curb cookie forgery
Photo: BleepingComputer
TL;DR

Microsoft released out-of-band security updates for a critical ASP.NET Core Data Protection vulnerability (CVE-2026-40372) that could let unauthenticated attackers forge authentication cookies and gain SYSTEM privileges. The flaw comes from a regression in the 10.0.0–10.0.6 NuGet packages, which could cause forged payloads to bypass authenticity checks; upgrading to 10.0.7 and redeploying with a rotated DataProtection key ring fixes the issue. This follows April’s Patch Tuesday and includes additional out-of-band Windows Server fixes. No service disruption is reported, but applications using DataProtection should update promptly to prevent token forgery and data exposure.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer