Microsoft Visual Studio 2026 Version 18.7 vulnerabilities
16 known vulnerabilities affecting microsoft/microsoft_visual_studio_2026_version_18.7.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-47303P2HIGHCVSS 8.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47303 [HIGH] CWE-90 CVE-2026-47303: Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to ele
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-47300P2HIGHCVSS 8.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47300 [HIGH] CWE-303 CVE-2026-47300: Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker t
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-47304P3CRITICALCVSS 9.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47304 [CRITICAL] CWE-345 CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50528P3HIGHCVSS 8.2≥ 18.0, < 18.7.42026-07-14
CVE-2026-50528 [HIGH] CWE-302 CVE-2026-50528: Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50527P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50527 [HIGH] CWE-121 CVE-2026-50527: Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50524P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50524 [HIGH] CWE-1287 CVE-2026-50524: Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50649P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-50649 [HIGH] CWE-502 CVE-2026-50649: Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-47302P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-47302 [HIGH] CWE-770 CVE-2026-47302: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50651P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50651 [HIGH] CWE-770 CVE-2026-50651: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50646P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-50646 [HIGH] CWE-502 CVE-2026-50646: Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50648P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50648 [HIGH] CWE-770 CVE-2026-50648: Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50525P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50525 [HIGH] CWE-770 CVE-2026-50525: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50650P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-50650 [HIGH] CWE-94 CVE-2026-50650: Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized a
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-47305P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47305 [HIGH] CWE-693 CVE-2026-47305: Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locall
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50659P3MEDIUMCVSS 6.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50659 [MEDIUM] CWE-116 CVE-2026-50659: Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-50526P4MEDIUMCVSS 5.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50526 [MEDIUM] CWE-59 CVE-2026-50526: Improper link resolution before file access ('link following') in .NET allows an authorized attacker
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
nvd