Microsoft Visual Studio 2022 — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Visual Studio 2022, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (146)
CVE-2025-55315 — CVSS 9.9 (critical): Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a…
CVE-2025-49739 — CVSS 8.8 (high): Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over…
CVE-2026-47303 — CVSS 8.8 (high): Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47300 — CVSS 8.8 (high): Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-21256 — CVSS 8.8 (high): Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an…
CVE-2026-50528 — CVSS 8.2 (high): Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-47304 — CVSS 8.1 (high): Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-21257 — CVSS 8.0 (high): Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an…
CVE-2025-26646 — CVSS 8.0 (high): External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform…
CVE-2025-32702 — CVSS 7.8 (high): Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to…
CVE-2025-53773 — CVSS 7.8 (high): Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an…
CVE-2026-47305 — CVSS 7.8 (high): Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2026-50646 — CVSS 7.8 (high): Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-32178 — CVSS 7.5 (high): Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-26682 — CVSS 7.5 (high): Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-50651 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50648 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50524 — CVSS 7.5 (high): Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47302 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62901 — CVSS 7.5 (high): Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-32203 — CVSS 7.5 (high): Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2025-24998 — CVSS 7.3 (high): Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-25003 — CVSS 7.3 (high): Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-29802 — CVSS 7.3 (high): Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-29804 — CVSS 7.3 (high): Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-55240 — CVSS 7.3 (high): Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2026-32177 — CVSS 7.3 (high): Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47959 — CVSS 7.1 (high): Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to…
CVE-2026-50526 — CVSS 7.0 (high): Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2025-24070 — CVSS 7.0 (high): Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62897 — CVSS 7.0 (high): Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2025-62214 — CVSS 6.7 (medium): Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to…
CVE-2026-62902 — CVSS 6.5 (medium): Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62900 — CVSS 5.9 (medium): Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a…
CVE-2025-32703 — CVSS 5.5 (medium): Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
CVE-2020-8927 — CVSS 5.3 (medium): A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot"…
CVE-2025-55248 — CVSS 4.8 (medium): Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.