Heap-based Buffer Overflow in Microsoft Visual Studio
CVE-2026-77906

8.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 September 2026

What is CVE-2026-77906?

A heap-based buffer overflow vulnerability exists in Microsoft Visual Studio, allowing unauthorized attackers to potentially execute arbitrary code over a network. This flaw can be exploited in scenarios where an attacker can craft specific inputs to manipulate memory allocations. Mitigation requires applying the appropriate security updates as provided in the vendor advisory.

Affected Version(s)

Microsoft Visual Studio 2026 version 18.9 18.9.0 < 18.9.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.