Microsoft’s April 2026 Patch Tuesday included an out-of-band critical elevation of privilege vulnerability in ASP.NET Core 10.0 (CVE-2026-40372, CVSS 9.1), addressed in the .NET 10.0.7 release. No active exploitation or confirmed IOCs are available at time of publication, but the out-of-band release cadence signals Microsoft’s internal urgency assessment. Organizations running ASP.NET Core 10.0 in production should apply .NET 10.0.7 under an emergency change window.