Security Feature Bypass in Visual Studio Code by Microsoft
CVE-2026-81376

9.6CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 September 2026

What is CVE-2026-81376?

A vulnerability in Visual Studio Code allows an unauthorized attacker to bypass critical security features due to incomplete comparisons. This flaw can be exploited over a network, potentially enabling unauthorized access to sensitive information or functionalities. Users of affected versions are advised to review their systems and apply the latest updates to mitigate risks associated with this exploit.

Affected Version(s)

Visual Studio Code 1.0.0 < 1.136.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.