« Volver al listado

Microsoft

Microsoft Visual Studio 2026: vulnerabilidades y CVE

Microsoft Visual Studio 2026 tiene 36 vulnerabilidades publicadas, 36 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE36
Últimos 12 meses36
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77907Alta (8.8)0.82%—8 sept 2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-77906Alta (8.8)0.82%—8 sept 2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-71328Alta (8.8)0.76%—8 sept 2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-69806Alta (7)0.76%—8 sept 2026
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-69805Alta (8.1)0.50%—8 sept 2026
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69439Alta (8.8)0.84%—8 sept 2026
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69304Media (5.9)0.88%—8 sept 2026
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-70354Alta (7.8)0.36%—11 ago 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62909Alta (7.8)0.26%—11 ago 2026
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62902Media (6.5)0.87%—11 ago 2026
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901Alta (7.5)1.2%—11 ago 2026
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62900Media (5.9)0.75%—11 ago 2026
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62899Media (5.9)0.75%—11 ago 2026
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62898Alta (7.5)1.0%—11 ago 2026
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897Alta (7)0.37%—11 ago 2026
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62886Alta (7.8)0.47%—11 ago 2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62871Alta (7.8)0.47%—11 ago 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50659Media (6.5)0.74%—14 jul 2026
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-50651Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50649Alta (7.8)4.0%—14 jul 2026
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50648Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50646Alta (7.8)4.0%—14 jul 2026
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50528Alta (8.2)0.61%—14 jul 2026
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50527Alta (7.5)1.2%—14 jul 2026
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50526Media (5.5)0.22%—14 jul 2026
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50525Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50524Alta (7.5)1.2%—14 jul 2026
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47305Alta (7.8)0.47%—14 jul 2026
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2026-47304Crítica (9.8)0.29%—14 jul 2026
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-47303Alta (8.8)0.84%—14 jul 2026
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter5
  2. T1203 Exploitation for Client Execution4
  3. T1068 Exploitation for Privilege Escalation2
  4. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft