visual_studio_2026_version_18.9 vulnerabilities
CVEs whose affected-version data names the visual_studio_2026_version_18.9 package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-69806High· 7.0Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-69805High· 7.5External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69522High· 8.8Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-69439High· 8.8Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69304Medium· 5.9Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-58649Medium· 6.5Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.