Microsoft patches critical ASP.NET Core vulnerability on macOS and Linux

Microsoft has released an emergency patch for a high-severity vulnerability in its ASP.NET Core framework, affecting macOS and Linux applications. Tracked as CVE-2026-40372, the flaw allows unauthenticated attackers to gain SYSTEM privileges through forged authentication payloads. The company advises immediate updates and key rotation to fully mitigate risks.

Microsoft released version 10.0.7 of the Microsoft.AspNetCore.DataProtection NuGet package on Tuesday to fix CVE-2026-40372, which carries a severity score of 9.1 out of 10. The issue affects versions 10.0.0 through 10.0.6 and stems from a regression bug in last week's update to 10.0.6. This bug caused faulty cryptographic signature verification during HMAC validation, enabling attackers to forge credentials and elevate privileges on non-Windows systems running ASP.NET Core apps. ASP.NET Core is a high-performance framework for .NET applications on platforms including macOS, Linux, and Docker. The vulnerability leaves devices open to full compromise if exploited during the vulnerable period. Even after patching, legitimately signed tokens issued to attackers—such as session refreshes, API keys, or password reset links—remain valid unless the DataProtection key ring is rotated, Microsoft warned. Affected users include those on macOS or Linux whose applications load version 10.0.6 at runtime, particularly if they do not target Microsoft.NET.Sdk.Web or have certain framework references without opting out of PrunePackageReference. Windows apps are unaffected due to different default encryptors. Microsoft urges updating to 10.0.7 immediately, rotating keys for internet-exposed endpoints, and auditing application artifacts created during vulnerability exposure.

Verwandte Artikel

Illustration depicting the Linux CopyFail vulnerability enabling root access exploits alongside Ubuntu's DDoS-induced outage.
Bild generiert von KI

Linux CopyFail exploit threatens root access amid Ubuntu outage

Von KI berichtet Bild generiert von KI

A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.

Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.

Von KI berichtet

Four days after the CopyFail (CVE-2026-31431) exploit disclosure disrupted Ubuntu services, the US government warned of its critical risks to Linux systems, urging immediate patching amid public exploit code.

A critical flaw in the Ghost content management system is being leveraged to target websites.

Diese Website verwendet Cookies

Wir verwenden Cookies für Analysen, um unsere Website zu verbessern. Lesen Sie unsere Datenschutzrichtlinie für weitere Informationen.
Ablehnen