CVE-2026-59113: Visual Studio Code Remote Code Execution Vulnerability
Published Aug 11, 2026
·Updated
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Other sources
Visual Studio Code Remote Code Execution Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Visual Studio Code<1.132.1
1.132.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.132.1
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-59113?
CVE-2026-59113 has a high severity rating of 8.8.
2
What software is affected by CVE-2026-59113?
CVE-2026-59113 affects Microsoft Visual Studio Code.
3
How can an attacker exploit CVE-2026-59113?
An attacker can exploit CVE-2026-59113 by executing unauthorized code over a network due to missing authorization.
4
What impact does CVE-2026-59113 have on users?
CVE-2026-59113 can lead to remote code execution, compromising the user's system and data.
5
Are there any mitigation steps available for CVE-2026-59113?
Mitigations for CVE-2026-59113 involve ensuring proper authorization checks before accessing remote code execution features.