Microsoft has released .NET 10.0.7 as an out-of-band security update to address CVE-2026-40372 in the Microsoft.AspNetCore.DataProtection NuGet package. A regression introduced in 10.0.6 caused decryption failures and exposed a vulnerability where the managed authenticated encryptor could compute its HMAC validation tag over
Sort: