Microsoft ASP.NET Security Update – 23 April 2026

Microsoft has released a security update to address a vulnerability that affects ASP.NET Core 10.0.

The addressed vulnerability could allow the remote unauthenticated attacker to gain SYSTEM privileges on the affected devices by forging authentication cookies.

The addressed vulnerability:

Microsoft ASP.NET Core 10.0 Improper Verification of Cryptographic Signature (CVE-2026-40372):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities

CVE-2026-40372

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft MSRC

References