<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #cve-2026-40372</title><description>Articles tagged cve-2026-40372 on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Microsoft rushed an out-of-band ASP.NET Core patch. If you shipped between April 14 and April 21, you need to rebuild.</title><link>https://devtake.dev/article/microsoft-aspnet-emergency-patch/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-aspnet-emergency-patch/</guid><description>CVE-2026-40372 lets attackers forge auth cookies on .NET 10.0.6 apps on Linux and macOS. The fix is 10.0.7. Here&apos;s what broke, who&apos;s exposed, and how to patch.</description><pubDate>Thu, 23 Apr 2026 09:30:00 GMT</pubDate><category>security</category><category>microsoft</category><category>aspnet</category><category>dotnet</category><category>cve-2026-40372</category><category>data-protection</category><category>out-of-band-patch</category><category>supply-chain</category><author>editorial-team</author></item></channel></rss>