Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
.NET 10.0.7 Update Fixes Critical Vulnerability

.NET 10.0.7 Update Fixes Critical Vulnerability

Posted on April 22, 2026 By CWS

Microsoft has urgently released a security update for .NET 10, specifically version 10.0.7, on April 21, 2026. This update addresses a critical elevation of privilege vulnerability found in the Microsoft.AspNetCore.DataProtection NuGet package.

Emergency Security Update Released

The decision to issue an out-of-band update followed customer reports of decryption failures within ASP.NET Core applications post the standard Patch Tuesday .NET 10.0.6 update. Developers noted these issues in ASP.NET Core issue #66335, leading to the discovery of a serious security regression affecting all package versions from 10.0.0 to 10.0.6.

Details of the Vulnerability

Identified as CVE-2026-40372, the flaw is rooted in the managed authenticated encryptor component of the package. The vulnerability arises from incorrect computation of the HMAC validation tag over payload bytes, allowing potential attackers to bypass integrity validation and escalate privileges. This undermines the security framework used for encrypting cookies, tokens, and sensitive data within ASP.NET Core applications.

Any application utilizing the Microsoft.AspNetCore.DataProtection package on .NET versions 10.0.0 to 10.0.6 is at risk. The package is integral for cookie authentication, anti-forgery tokens, and TempData encryption, highlighting a significant potential attack surface for unpatched systems.

Immediate Action Required

Microsoft strongly advises developers and organizations using affected versions to update to version 10.0.7 without delay. The updated SDK and runtime can be downloaded from the official .NET 10.0 download page. Administrators should verify the update by running dotnet –info and ensure applications are rebuilt and redeployed using the updated NuGet packages or container images.

Updated container images are accessible via the Microsoft Container Registry, and specific instructions for Linux package installations are available for server deployments. Documentation on known issues for the 10.0 release is provided in the .NET Core GitHub repository.

Security Landscape and Future Precautions

This emergency patch reflects Microsoft’s proactive stance in accelerating security fixes beyond its usual Patch Tuesday schedule when critical threats are identified. The April 2026 Patch Tuesday addressed several privilege escalation vulnerabilities, emphasizing the ongoing security challenges within Microsoft’s ecosystem. Developers are encouraged to enable automatic NuGet package updates to quickly respond to future out-of-band releases.

For continuous updates on cybersecurity developments, follow us on Google News, LinkedIn, and X. For inquiries or to share your stories, please contact us directly.

Cyber Security News Tags:.NET 10.0.7, ASP.NET Core, CVE-2026-40372, data protection, elevation of privilege, Encryption, Microsoft, NuGet, Patch Tuesday, security update, Vulnerability

Post navigation

Previous Post: Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms
Next Post: Microsoft File Exploited in India-Focused Cyber Espionage

Related Posts

WordPress Post SMTP Plugin Vulnerability Exposes 400,000 Websites to Account Takeover Attacks WordPress Post SMTP Plugin Vulnerability Exposes 400,000 Websites to Account Takeover Attacks Cyber Security News
Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses Cyber Security News
0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail 0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail Cyber Security News
Apache Tomcat Security Vulnerabilities Expose Servers to Remote Code Execution Attacks Apache Tomcat Security Vulnerabilities Expose Servers to Remote Code Execution Attacks Cyber Security News
SpankRAT Threatens Windows Security with Stealth Techniques SpankRAT Threatens Windows Security with Stealth Techniques Cyber Security News
Comcast to Pay a .5 Million Fine to Settle an FCC Investigation Linked to Vendor Data Breach Comcast to Pay a $1.5 Million Fine to Settle an FCC Investigation Linked to Vendor Data Breach Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft File Exploited in India-Focused Cyber Espionage
  • .NET 10.0.7 Update Fixes Critical Vulnerability
  • Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms
  • Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit
  • PureRAT Malware Utilizes PNG Files for Stealthy Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft File Exploited in India-Focused Cyber Espionage
  • .NET 10.0.7 Update Fixes Critical Vulnerability
  • Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms
  • Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit
  • PureRAT Malware Utilizes PNG Files for Stealthy Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark