Microsoft issues emergency update for macOS and Linux ASP.NET threat

TL;DR AI
2 min readKey summary
Microsoft issued an emergency ASP.NET Core patch for CVE-2026-40372, a high-severity flaw in Microsoft.AspNetCore.DataProtection 10.0.0 through 10.0.6.
The bug could let unauthenticated attackers forge authentication payloads and gain SYSTEM-level privileges on affected macOS and Linux apps.
Microsoft warned that patching alone may not invalidate previously issued signed tokens.
Administrators should rotate the DataProtection key ring after upgrading to prevent attacker-issued tokens from remaining usable.



