CVE-2026-40372
published 2026-04-21CVE-2026-40372: Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
PriorityP270critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
11.21%
95.5th percentile
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | >= 10.0.0 < 10.0.7 | 10.0.7 |
| microsoft | asp.net_core_10.0 | >= 10.0 < 10.0.7 | 10.0.7 |
| microsoft | microsoft_visual_studio_2026_version_18.5 | >= 18.5.0 < 18.5.2 | 18.5.2 |
| ubuntu | dotnet10 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Scope detection to non-Windows (Linux, macOS) hosts running ASP.NET Core with the NuGet copy of Microsoft.AspNetCore.DataProtection loaded at runtime — the vulnerability does not trigger on Windows. ↗
- →After upgrading to 10.0.7, audit for tokens (session refresh, API keys, password reset links) issued during the vulnerable window — they remain valid until the DataProtection key ring is rotated. ↗
- →Watch for privilege escalation to SYSTEM on Linux/macOS ASP.NET Core services as a post-exploitation indicator of successful CVE-2026-40372 abuse. ↗
- ·Exploitation requires the NuGet copy of the library to be actually loaded at runtime — not just referenced. Applications using the inbox (non-NuGet) version are not affected. ↗
- ·No Red Hat products are affected; the vulnerability is specific to Microsoft.AspNetCore.DataProtection 10.0.6 from NuGet. ↗
- ·After patching to 10.0.7, rotating the DataProtection key ring is recommended to invalidate any tokens issued during the vulnerable window. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ghsa9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
ghsa·2026-04-23·CVSS 9.1
CVE-2026-40372 [CRITICAL] CWE-347 Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
## Executive Summary:
A bug in `Microsoft.AspNetCore.DataProtection` 10.0.0-10.0.6 NuGet packages can give an attacker the opportunity to execute an Elevation of Privilege attack by forging authentication cookies, and also allows some protected payloads to be decrypted.
If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue **legitimately-signed** tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated.
This is comparable in capability to [MS10-070](https://learn.microsoft.com/en-us/security-updat
VulDB
Microsoft ASP.NET Core up to 10.0.6 signature verification
vuldb·2026-04-21·CVSS 9.1
CVE-2026-40372 [CRITICAL] Microsoft ASP.NET Core up to 10.0.6 signature verification
A vulnerability classified as problematic was found in Microsoft ASP.NET Core up to 10.0.6. The impacted element is an unknown function. The manipulation results in improper verification of cryptographic signature.
This vulnerability is identified as CVE-2026-40372. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2026-04-28·CVSS 7.5
CVE-2026-33116 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
Ludvig Pedersen discovered that the System.Security.Cryptography.Xml
library in .NET incorrectly handled certain XML inputs. An attacker could
possibly use this issue to consume excessive resources, resulting in a
denial of service. (CVE-2026-33116, CVE-2026-26171)
Ludvig Pedersen and Kevin Jones discovered that the
System.Security.Cryptography.Xml library in .NET incorrectly handled
certain XML inputs. An attacker could possibly use this issue to cause
.NET to crash, resulting in a denial of service. (CVE-2026-32203)
Ludvig Pedersen discovered that the System.Net.Mail component in .NET
incorrectly handled certain inputs. An attacker could possibly use this
issue to perform a network spoofing attack. (CVE-
Ubuntu
.NET vulnerability
vendor_ubuntu·2026-04-28
CVE-2026-40372 .NET vulnerability
Title: .NET vulnerability
Summary: .NET could be made to crash or run programs as an administrator.
It was discovered that the Microsoft.AspNetCore.DataProtection library in
.NET did not properly verify cryptographic signatures under certain
conditions. A remote attacker could possibly use this issue to elevate
privileges.
Instructions: After a standard system update, it is recommended to rotate the
DataProtection key ring.
Red Hat
ASP.NET Core: ASP.NET: ASP.NET Core: Privilege escalation via improper cryptographic signature verification
vendor_redhat·2026-04-21·CVSS 9.1
CVE-2026-40372 [CRITICAL] CWE-347 ASP.NET Core: ASP.NET: ASP.NET Core: Privilege escalation via improper cryptographic signature verification
ASP.NET Core: ASP.NET: ASP.NET Core: Privilege escalation via improper cryptographic signature verification
A flaw was found in ASP.NET Core due to improper verification of cryptographic signatures. An unauthorized attacker can exploit this vulnerability remotely over a network, leading to privilege escalation.
Statement: No Red Hat products are affected as this vulnerability is specific to Microsoft.AspNetCore.DataProtection 10.0.6 from NuGet.
Package: dotnet9.0 (Red Hat Enterprise Linux 10) - Not affected
Package: dotnet9.0 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet9.0 (Red Hat Enterprise Linux 9) - Not affected
Package: dotnet10.0 (Red Hat Hardened Images) - Not affected
Package: dotnet9.0 (Red Hat Hardened Images) - Not affected
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
blogs_hackernews·2026-04-27
CVE-2025-20333 ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are.
Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust. Same mess, cleaner packaging.
Coffee is cold. The vuln list is ugly. Let’s get into it.
## ⚡ Threat of the Week
New fast16 Malware Was Developed Y
Checkpoint
27th April – Threat Intelligence Report
blogs_checkpoint·2026-04-27
CVE-2025-55182 27th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Vercel, a frontend cloud platform, has disclosed a security incident linked to a compromise at Context.ai, where stolen OAuth tokens enabled unauthorized access through a connected app. The company reported access to employee information, internal logs, and a subset of environment variables, while stating that the most sensiti
Hackernews
Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
blogs_hackernews·2026-04-22·CVSS 9.1
CVE-2026-40372 [CRITICAL] Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
Microsoft has released out-of-band updates to address a security vulnerability in ASP.NET Core that could allow an attacker to escalate privileges.
The vulnerability, tracked as CVE-2026-40372 , carries a CVSS score of 9.1 out of 10.0. It's rated Important in severity. An anonymous researcher has been credited with discovering and reporting the flaw.
"Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network," Microsoft said in a Tuesday advisory. "An attacker who succes
Bugzilla
CVE-2026-40372 ASP.NET Core: ASP.NET: ASP.NET Core: Privilege escalation via improper cryptographic signature verification
bugzilla·2026-04-21·CVSS 9.1
CVE-2026-40372 [CRITICAL] CVE-2026-40372 ASP.NET Core: ASP.NET: ASP.NET Core: Privilege escalation via improper cryptographic signature verification
CVE-2026-40372 ASP.NET Core: ASP.NET: ASP.NET Core: Privilege escalation via improper cryptographic signature verification
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
2026-04-21
Published