SB2026090910 - Multiple vulnerabilities in Visual Studio
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Origin validation error (CVE-ID: CVE-2026-58649)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an origin validation error in .NET when validating origins. A remote attacker can exploit the vulnerability to disclose sensitive information.
User interaction is required. Successful exploitation could expose developer-time hot reload data, including application metadata, intermediate language updates, debugging information, method names, string literals, and file paths.
2) Improper handling of highly compressed data (CVE-ID: CVE-2026-69304)
CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data (data amplification) in ASP.NET Core when processing highly compressed data. A remote attacker can send highly compressed data to cause a denial of service.
3) Heap-based buffer overflow (CVE-ID: CVE-2026-69439)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute code with the privileges of the affected process.
The vulnerability exists due to a heap-based buffer overflow in .NET and Visual Studio when processing a specially crafted Portable PDB file. A remote attacker can convince a user or service to process a specially crafted Portable PDB file to execute code with the privileges of the affected process.
4) Heap-based buffer overflow (CVE-ID: CVE-2026-69522)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Visual Studio when a user opens a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
5) External Control of File Name or Path (CVE-ID: CVE-2026-69805)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to elevate privileges.
The vulnerability exists due to external control of file name or path in .NET when handling externally controlled file names or paths. A remote attacker can win a race condition involving an externally controlled file name or path to elevate privileges.
User interaction is required for exploitation.
6) Information disclosure (CVE-ID: CVE-2026-69806)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in .NET for Linux when local users can access process information through the proc filesystem. A local user can access exposed process information to elevate privileges.
Successful exploitation requires a Linux environment in which users share a process identifier namespace. The attacker can gain the privileges of the user account or service account running the affected process.
7) Heap-based buffer overflow (CVE-ID: CVE-2026-71328)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Visual Studio when opening a specially crafted file. A remote attacker can trick a user into opening a specially crafted file to execute arbitrary code.
User interaction is required.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-58649
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69304
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69439
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69522
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69805
- https://www.nuget.org/packages/Microsoft.Diagnostics.Runtime
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69806
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-71328