Impact
A heap‑based buffer overflow in the 2026 edition of Microsoft Visual Studio allows an attacker that can send data to the application to induce execution of arbitrary code. The flaw directly leads to remote code execution, making it a severe threat to confidentiality, integrity, and availability of systems that have not been patched.
Affected Systems
Microsoft Visual Studio 2026, specifically version 18.9, is affected by this vulnerability. Users of earlier or later releases beyond 18.9 are not known to be impacted per the available vendor information.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.8, categorizing it as high severity. Without an EPSS score the exact likelihood of exploitation is unclear, but the fact that the flaw is network‑exposed indicates that an attacker could potentially reach it over a local network or beyond if the software is accessible. The vulnerability is not listed in the CISA KEV catalog, and no exploit has been reported to date. However, the nature of the overflow, combined with the high CVSS, makes it a priority to remediate before an exploit is discovered or widely distributed.
OpenCVE Enrichment