An updated version of the April 2026 Scan Cab is available
IMPORTANT: This notice is only relevant for environments where:

- ASP.NET Core is used
- Scan Cab is used to check for update compliance
- The April 2026 Scan Cab was deployed before 10:00 PM PT on April 21, 2026
An updated version of the April 2026 Scan Cab was made available at 10:00 PM PT on April 21, 2026. This Scan Cab includes new metadata corresponding to updates for ASP.NET Core.
The Microsoft update for ASP.NET Core released on April 21, 2026, includes additional protections to address CVE-2026-40372: ASP.NET Core Elevation of Privilege Vulnerability. See the Additional information section of this message for details.
How this affects your organization:
IT administrators who downloaded the Scan Cab before 10:00 PM PT on April 21, 2026, should re-acquire and re-deploy it if the Scan Cab is used to assess updates for environments where ASP.NET Core is used.
No action is required for environments where Scan Cab is not employed or ASP.NET Core is not used. However, please note that there might be non-Microsoft applications that utilize Scan Cab. Review the documentation for any software and update deployment tools used in your organization to determine whether this applies to your environment.
What you need to do to prepare:
Administrators can download and deploy the updated Scan Cab using their usual processes. For more information, see the Additional information section below.
Additional information:
- Updated Scan Cab: Download the new Scan Cab here
- CVE-2026-40372: ASP.NET Core Elevation of Privilege Vulnerability
- Announcing a smaller WSUS Scan Cab – Microsoft Tech Community: Learn more about WSUS and the Scan Cab process
- Using WUA to Scan for Updates Offline – Win32 apps | Microsoft Docs: Windows Update Agent (WUA) can be used to scan computers for security updates without connecting to Windows Update
- WSUS and the Catalog Site | Microsoft Docs: The Catalog Site used by WSUS to import updates and drivers
Message ID: MC1287681

HANDS ON tek
M365 Admin


