A cryptographic signature verification flaw in ASP.NET Core’s Data Protection library lets an unauthenticated attacker forge authentication cookies and other protected payloads, allowing impersonation of privileged users on Linux-hosted applications running Microsoft.AspNetCore.DataProtection 10.0.0 through 10.0.6.
Read more about Emerging Threat: (CVE-2026-40372) ASP.NET Core Privilege Escalation via Signature Bypass