Microsoft issues emergency update for macOS and Linux ASP.NET threat
When authentication fails, things can go very, very wrong.
Signal weather
Stable
The story has moved beyond the first headline and now acts as a reliable context anchor.
Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps. The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft. AspNetCore. DataProtection NuGet, a package that’s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server. Beware: Forged credentials survive patching During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged. Read full article Comments
Stay on the signal
Follow Microsoft issues emergency update for macOS and Linux ASP.NET threat
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Entity pages
Story threads
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a steady pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
2
Related articles
More stories that share tags, source, or category context.
Man jailed for a month despite Flock showing he was 5 miles from crime scene
Cop seemingly ignored Flock camera timestamp to justify arrests.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
F1 in Monaco: Finally, the cars were flat-out in qualifying
The cars are too big to race well, but the competition for pole position is thrilling.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
A Falcon 9 booster turns 5 years old—and just set a remarkable reuse record
We take the Falcon 9 rocket for granted. But we probably shouldn't.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Michigan politicians want to ban Chinese-badged cars from even visiting the US
The latest bill would ban day trips from Canada or Mexico in Chinese cars.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Man jailed for a month despite Flock showing he was 5 miles from crime scene
Cop seemingly ignored Flock camera timestamp to justify arrests.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
F1 in Monaco: Finally, the cars were flat-out in qualifying
The cars are too big to race well, but the competition for pole position is thrilling.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
A Falcon 9 booster turns 5 years old—and just set a remarkable reuse record
We take the Falcon 9 rocket for granted. But we probably shouldn't.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Michigan politicians want to ban Chinese-badged cars from even visiting the US
The latest bill would ban day trips from Canada or Mexico in Chinese cars.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.