Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
.NET 10.0.7 Update Fixes Critical Vulnerability

.NET 10.0.7 Update Fixes Critical Vulnerability

Posted on April 22, 2026 By CWS

Microsoft has urgently released a security update for .NET 10, specifically version 10.0.7, on April 21, 2026. This update addresses a critical elevation of privilege vulnerability found in the Microsoft.AspNetCore.DataProtection NuGet package.

Emergency Security Update Released

The decision to issue an out-of-band update followed customer reports of decryption failures within ASP.NET Core applications post the standard Patch Tuesday .NET 10.0.6 update. Developers noted these issues in ASP.NET Core issue #66335, leading to the discovery of a serious security regression affecting all package versions from 10.0.0 to 10.0.6.

Details of the Vulnerability

Identified as CVE-2026-40372, the flaw is rooted in the managed authenticated encryptor component of the package. The vulnerability arises from incorrect computation of the HMAC validation tag over payload bytes, allowing potential attackers to bypass integrity validation and escalate privileges. This undermines the security framework used for encrypting cookies, tokens, and sensitive data within ASP.NET Core applications.

Any application utilizing the Microsoft.AspNetCore.DataProtection package on .NET versions 10.0.0 to 10.0.6 is at risk. The package is integral for cookie authentication, anti-forgery tokens, and TempData encryption, highlighting a significant potential attack surface for unpatched systems.

Immediate Action Required

Microsoft strongly advises developers and organizations using affected versions to update to version 10.0.7 without delay. The updated SDK and runtime can be downloaded from the official .NET 10.0 download page. Administrators should verify the update by running dotnet –info and ensure applications are rebuilt and redeployed using the updated NuGet packages or container images.

Updated container images are accessible via the Microsoft Container Registry, and specific instructions for Linux package installations are available for server deployments. Documentation on known issues for the 10.0 release is provided in the .NET Core GitHub repository.

Security Landscape and Future Precautions

This emergency patch reflects Microsoft’s proactive stance in accelerating security fixes beyond its usual Patch Tuesday schedule when critical threats are identified. The April 2026 Patch Tuesday addressed several privilege escalation vulnerabilities, emphasizing the ongoing security challenges within Microsoft’s ecosystem. Developers are encouraged to enable automatic NuGet package updates to quickly respond to future out-of-band releases.

For continuous updates on cybersecurity developments, follow us on Google News, LinkedIn, and X. For inquiries or to share your stories, please contact us directly.

Cyber Security News Tags:.NET 10.0.7, ASP.NET Core, CVE-2026-40372, data protection, elevation of privilege, Encryption, Microsoft, NuGet, Patch Tuesday, security update, Vulnerability

Post navigation

Previous Post: Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms
Next Post: Microsoft File Exploited in India-Focused Cyber Espionage

Related Posts

Ransomware Groups Exploit AzCopy for Data Theft Ransomware Groups Exploit AzCopy for Data Theft Cyber Security News
Security Alert: macOS textutil and KeePassXC Risks Security Alert: macOS textutil and KeePassXC Risks Cyber Security News
Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges Cyber Security News
Frentree Partners with AccuKnox to Expand Zero Trust CNAPP Security in South Korea Frentree Partners with AccuKnox to Expand Zero Trust CNAPP Security in South Korea Cyber Security News
One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM Cyber Security News
WhatsApp Introduces New Security Alerts for Unknown Numbers WhatsApp Introduces New Security Alerts for Unknown Numbers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark