CVE-2026-71328High· 8.8▾ TwilightHeap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
Last analysed / modified upstream
0.6% → 0.8%
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
visual_studio_2022 >= 17.14.0, < 17.14.40visual_studio_2026 >= 18.9.0, < 18.9.3.net >= 8.0.0, < 8.0.31.net >= 9.0.0, < 9.0.20.net >= 10.0.0, < 10.0.12.net = 11.0.0Upgrade past the affected range:
visual_studio_2022 17.14.40visual_studio_2026 18.9.3.net 10.0.12Affected packages:
Microsoft.DiaSymReader.Native >= 17.10.0-beta1.24272.1, <= 18.9.0-beta1.26405.1Patched in:
Microsoft.DiaSymReader.Native 18.9.0-beta1.26405.2Connected by shared product, vendor, weakness, or advisory.
GHSA-4qhr-qf46-fcrxHigh· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2026-62886High· 7.8Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-69486High· 8.8Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
GHSA-mqvm-gmc4-6rv2High· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
GHSA-q72m-f2r4-w4cwHigh· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.