PT-2026-34051 · Microsoft · Asp.Net Core 10.0

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-40372

CVSS v3.1

9.1

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ASP.NET Core versions prior to 10.0.7
Description Improper verification of cryptographic signature in the Microsoft.AspNetCore.DataProtection component allows an unauthorized attacker to elevate privileges over a network.
Recommendations Update to version 10.0.7.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2026-40372

Affected Products

Asp.Net Core 10.0