TechApr 22, 2026Microsoft Patches ASP.NET Core Privilege Escalation CVE-2026-40372A regression in cryptographic signature validation introduced a CVSS 9.1 flaw into .NET 10.0. The Data Protection API implemented HMAC verification incompletely, opening the door to padding oracle attacks and forged authentication tokens.SecurityASP.NET Core.NETCVEVulnerabilityCryptography