Heap-Based Buffer Overflow in Visual Studio by Microsoft
CVE-2026-77907

8.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 September 2026

What is CVE-2026-77907?

A heap-based buffer overflow vulnerability in Visual Studio may allow an unauthorized attacker to execute arbitrary code remotely. This weakness can be exploited during specific network interactions, posing a significant risk to the integrity of the software and potentially leading to unauthorized access or system compromise. It's essential for users and administrators to apply the latest security patches and updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Microsoft Visual Studio 2026 version 18.9 18.9.0 < 18.9.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.