Microsoft
Microsoft Visual Studio 2026: vulnerabilidades y CVE
Microsoft Visual Studio 2026 tiene 36 vulnerabilidades publicadas, 36 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses36
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77907 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2026-77906 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2026-71328 | Alta (8.8) | 0.76% | — | 8 sept 2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69806 | Alta (7) | 0.76% | — | 8 sept 2026 | Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69805 | Alta (8.1) | 0.50% | — | 8 sept 2026 | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69439 | Alta (8.8) | 0.84% | — | 8 sept 2026 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69304 | Media (5.9) | 0.88% | — | 8 sept 2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2026-70354 | Alta (7.8) | 0.36% | — | 11 ago 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-62909 | Alta (7.8) | 0.26% | — | 11 ago 2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62902 | Media (6.5) | 0.87% | — | 11 ago 2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62901 | Alta (7.5) | 1.2% | — | 11 ago 2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-62900 | Media (5.9) | 0.75% | — | 11 ago 2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62899 | Media (5.9) | 0.75% | — | 11 ago 2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-62898 | Alta (7.5) | 1.0% | — | 11 ago 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62897 | Alta (7) | 0.37% | — | 11 ago 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-62886 | Alta (7.8) | 0.47% | — | 11 ago 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-62871 | Alta (7.8) | 0.47% | — | 11 ago 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50659 | Media (6.5) | 0.74% | — | 14 jul 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-50651 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50649 | Alta (7.8) | 4.0% | — | 14 jul 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50648 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50646 | Alta (7.8) | 4.0% | — | 14 jul 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-50528 | Alta (8.2) | 0.61% | — | 14 jul 2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-50527 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50526 | Media (5.5) | 0.22% | — | 14 jul 2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. |
| CVE-2026-50525 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50524 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-47305 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. |
| CVE-2026-47304 | Crítica (9.8) | 0.29% | — | 14 jul 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-47303 | Alta (8.8) | 0.84% | — | 14 jul 2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.