ZeroHour

CVE-2026-77906

mass

Heap-Based Buffer Overflow in Microsoft Visual Studio Enables Network Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-77906 is a heap-based buffer overflow (CWE-122) in Microsoft Visual Studio, rated high severity (CVSS 3.1: 8.8) for remote code execution. The flaw is reachable over a network by an unauthenticated attacker, but the CVSS vector requires user interaction (UI:R), meaning a developer most likely triggers it by opening or processing attacker-supplied content, such as a crafted file or project. Successful exploitation would let the attacker execute arbitrary code in the context of Visual Studio with high impact on confidentiality, integrity, and availability of the affected workstation. Any organization running affected Visual Studio installations is potentially exposed, although the available data does not specify which version ranges are affected, so defenders should consult Microsoft's advisory. There is currently no evidence of active exploitation: the CVE is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.8% probability of exploitation in the next 30 days (53rd percentile).

What to do: Check the Microsoft Security Response Center advisory for CVE-2026-77906 to identify the affected Visual Studio version ranges and apply the published security update as soon as it is available. Until patched, have developers avoid opening untrusted files, projects, or network-supplied content in Visual Studio, since exploitation requires user interaction. Monitor KEV, EPSS, and vendor updates for signs of active exploitation or public PoC code.

Affected
Microsoft Visual Studio
Estimated exposure
mass≈ millions of developer installations worldwide (Visual Studio is one of the most widely deployed IDEs); exact affected-version install counts unknown — Estimated from Visual Studio's very large global developer install base and its prevalence in enterprise development environments; no per-version install counts or internet-exposure scan data are provided in the source data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
visual studio 2026
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.