cbcvebase.

Microsoft Visual Studio 2026 Version 18.7 vulnerabilities

16 known vulnerabilities affecting microsoft/microsoft_visual_studio_2026_version_18.7.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-47303P2HIGHCVSS 8.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47303 [HIGH] CWE-90 CVE-2026-47303: Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to ele Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-47300P2HIGHCVSS 8.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47300 [HIGH] CWE-303 CVE-2026-47300: Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker t Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-47304P3CRITICALCVSS 9.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47304 [CRITICAL] CWE-345 CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50528P3HIGHCVSS 8.2≥ 18.0, < 18.7.42026-07-14
CVE-2026-50528 [HIGH] CWE-302 CVE-2026-50528: Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50527P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50527 [HIGH] CWE-121 CVE-2026-50527: Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50524P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50524 [HIGH] CWE-1287 CVE-2026-50524: Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50649P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-50649 [HIGH] CWE-502 CVE-2026-50649: Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-47302P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-47302 [HIGH] CWE-770 CVE-2026-47302: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50651P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50651 [HIGH] CWE-770 CVE-2026-50651: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50646P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-50646 [HIGH] CWE-502 CVE-2026-50646: Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50648P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50648 [HIGH] CWE-770 CVE-2026-50648: Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50525P3HIGHCVSS 7.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50525 [HIGH] CWE-770 CVE-2026-50525: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50650P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-50650 [HIGH] CWE-94 CVE-2026-50650: Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized a Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-47305P3HIGHCVSS 7.8≥ 18.0, < 18.7.42026-07-14
CVE-2026-47305 [HIGH] CWE-693 CVE-2026-47305: Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locall Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50659P3MEDIUMCVSS 6.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50659 [MEDIUM] CWE-116 CVE-2026-50659: Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-50526P4MEDIUMCVSS 5.5≥ 18.0, < 18.7.42026-07-14
CVE-2026-50526 [MEDIUM] CWE-59 CVE-2026-50526: Improper link resolution before file access ('link following') in .NET allows an authorized attacker Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
nvd
Microsoft Visual Studio 2026 Version 18.7 vulnerabilities | cvebase