CVE-2026-62886High· 7.8▾ TwilightInteger overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Aug 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
visual_studio_2022 >= 17.14.0, < 17.14.38visual_studio_2026 >= 18.8.0, < 18.8.3.net >= 8.0.0, < 8.0.30.net >= 9.0.0, < 9.0.19.net >= 10.0.0, < 10.0.11Upgrade past the affected range:
visual_studio_2022 17.14.38visual_studio_2026 18.8.3.net 10.0.11Affected packages:
Microsoft.WindowsDesktop.App.Runtime.win-arm64 >= 10.0.0, <= 10.0.10Microsoft.WindowsDesktop.App.Runtime.win-x64 >= 10.0.0, <= 10.0.10Microsoft.WindowsDesktop.App.Runtime.win-x86 >= 10.0.0, <= 10.0.10Microsoft.WindowsDesktop.App.Runtime.win-arm64 >= 9.0.0, <= 9.0.18Microsoft.WindowsDesktop.App.Runtime.win-x64 >= 9.0.0, <= 9.0.18Microsoft.WindowsDesktop.App.Runtime.win-x86 >= 9.0.0, <= 9.0.18Microsoft.WindowsDesktop.App.Runtime.win-arm64 >= 8.0.0, <= 8.0.29Microsoft.WindowsDesktop.App.Runtime.win-x64 >= 8.0.0, <= 8.0.29Microsoft.WindowsDesktop.App.Runtime.win-x86 >= 8.0.0, <= 8.0.29Patched in:
Microsoft.WindowsDesktop.App.Runtime.win-arm64 10.0.11Microsoft.WindowsDesktop.App.Runtime.win-x64 10.0.11Microsoft.WindowsDesktop.App.Runtime.win-x86 10.0.11Microsoft.WindowsDesktop.App.Runtime.win-arm64 9.0.19Microsoft.WindowsDesktop.App.Runtime.win-x64 9.0.19Microsoft.WindowsDesktop.App.Runtime.win-x86 9.0.19Microsoft.WindowsDesktop.App.Runtime.win-arm64 8.0.30Microsoft.WindowsDesktop.App.Runtime.win-x64 8.0.30Microsoft.WindowsDesktop.App.Runtime.win-x86 8.0.30Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71328High· 8.8Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-84000High· 7.8Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
CVE-2026-81959High· 7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-69486High· 8.8Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
GHSA-mqvm-gmc4-6rv2High· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
GHSA-4qhr-qf46-fcrxHigh· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability