Description
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Update
AI Analysis

Impact

A heap-based buffer overflow is present in Microsoft Visual Studio 2026 that allows an unauthorized attacker to execute code remotely. The flaw occurs when the application processes network input, leading to uncontrolled memory writes that can be leveraged to run arbitrary code with the privileges of the Visual Studio process.

Affected Systems

Microsoft Visual Studio 2026, version 18.9, is affected. No other vendors or products are listed as impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating a high severity of exploitation. The EPSS score is not available, so the current exploitation probability cannot be quantified. It is not listed in CISA’s KEV catalog. The likely attack vector is through a network connection to a vulnerable Visual Studio instance, allowing an attacker to trigger the overflow and execute arbitrary code.

Generated by OpenCVE AI on September 9, 2026 at 21:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Visual Studio 2026 update that resolves the heap-based buffer overflow as described in the Microsoft Security Response Center update guide.
  • If a patch is not yet available, isolate the development environment by blocking external network access to the machine hosting Visual Studio or disabling any network‑exposed services such as the debugger or telemetry.
  • Run Visual Studio with the minimum required user privileges and segment the development workstation from critical production resources to reduce the blast radius of any code execution.

Generated by OpenCVE AI on September 9, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Title Visual Studio Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft visual Studio 2026
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:31.093Z

Reserved: 2026-08-21T17:26:55.613Z

Link: CVE-2026-77907

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:19.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:40.873

Modified: 2026-09-10T14:34:25.657

Link: CVE-2026-77907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:05:33Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow