CVE-2026-77906: Visual Studio Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Other sources
Visual Studio Remote Code Execution Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Visual Studio 2026=18.9
18.9.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.3
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
DescriptionSeverity
Data Sourced
via NVD·06:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can an attacker exploit this without an account or prior privileges?
The vector indicates no privileges are required, but user interaction is required. Exploitation is network-based and depends on a user taking an action.
2
Which product is identified as affected?
The affected software listed is Microsoft Visual Studio 2026.
3
Is an official remediation available?
The remediation level is listed as an official fix. The reference provided is the Microsoft security update guide entry for this CVE.