Microsoft Visual Studio 2026 — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Visual Studio 2026, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (29)
CVE-2026-47300 — CVSS 8.8 (high): Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47303 — CVSS 8.8 (high): Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-50528 — CVSS 8.2 (high): Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-47304 — CVSS 8.1 (high): Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50527 — CVSS 7.5 (high): Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47302 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62898 — CVSS 7.5 (high): Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-50525 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50648 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-62901 — CVSS 7.5 (high): Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50651 — CVSS 7.5 (high): Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50524 — CVSS 7.5 (high): Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-32203 — CVSS 7.5 (high): Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-45591 — CVSS 7.5 (high): Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-32177 — CVSS 7.3 (high): Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50526 — CVSS 7.0 (high): Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-62897 — CVSS 7.0 (high): Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62902 — CVSS 6.5 (medium): Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-50659 — CVSS 6.5 (medium): Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-62899 — CVSS 5.9 (medium): Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a…
CVE-2026-62900 — CVSS 5.9 (medium): Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a…
CVE-2026-32175 — CVSS 4.3 (medium): A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this…