CVE-2026-71328: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
Other sources
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.31 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.40 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0 RC1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.20
Event History
Frequently Asked Questions
Which systems should be prioritized for review?
Prioritize Windows systems with Microsoft Visual Studio 2026 or Visual Studio 2022, and systems with Microsoft .NET 8.0, 9.0, 10.0, or 11.0 installed on Windows.
What level of access does an attacker need to exploit this issue?
The vulnerability is network-reachable and does not require attacker privileges. Exploitation requires user interaction, while the attack complexity is rated low.