Microsoft
Microsoft Visual Studio 2022: vulnerabilities and CVEs
Microsoft Visual Studio 2022 has 151 published vulnerabilities, 39 of them in the last 12 months. 6 are rated critical and 2 are listed by CISA as actively exploited.
CVEs151
Last 12 months39
Critical6
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44487 | High (7.5) | 100% | ⚠ Active exploitation | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-38180 | High (7.5) | 14% | ⚠ Active exploitation | Aug 8, 2023 | .NET and Visual Studio Denial of Service Vulnerability |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71328 | High (8.8) | 0.76% | — | Sep 8, 2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69806 | High (7) | 0.76% | — | Sep 8, 2026 | Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69805 | High (8.1) | 0.50% | — | Sep 8, 2026 | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69439 | High (8.8) | 0.84% | — | Sep 8, 2026 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69304 | Medium (5.9) | 0.88% | — | Sep 8, 2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2026-70354 | High (7.8) | 0.36% | — | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-62909 | High (7.8) | 0.26% | — | Aug 11, 2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62902 | Medium (6.5) | 0.87% | — | Aug 11, 2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62901 | High (7.5) | 1.2% | — | Aug 11, 2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-62900 | Medium (5.9) | 0.75% | — | Aug 11, 2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62899 | Medium (5.9) | 0.75% | — | Aug 11, 2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-62898 | High (7.5) | 1.0% | — | Aug 11, 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62897 | High (7) | 0.37% | — | Aug 11, 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-62886 | High (7.8) | 0.47% | — | Aug 11, 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-62871 | High (7.8) | 0.47% | — | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50659 | Medium (6.5) | 0.74% | — | Jul 14, 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-50651 | High (7.5) | 1.2% | — | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50648 | High (7.5) | 1.2% | — | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50646 | High (7.8) | 4.0% | — | Jul 14, 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-50528 | High (8.2) | 0.61% | — | Jul 14, 2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-50527 | High (7.5) | 1.2% | — | Jul 14, 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50526 | Medium (5.5) | 0.22% | — | Jul 14, 2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. |
| CVE-2026-50525 | High (7.5) | 1.2% | — | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50524 | High (7.5) | 1.2% | — | Jul 14, 2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-47305 | High (7.8) | 0.47% | — | Jul 14, 2026 | Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. |
| CVE-2026-47304 | Critical (9.8) | 0.29% | — | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-47303 | High (8.8) | 0.84% | — | Jul 14, 2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-47302 | High (7.5) | 1.2% | — | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-47300 | High (8.8) | 0.78% | — | Jul 14, 2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-32177 | High (7.3) | 0.57% | — | May 12, 2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.