ZeroHour

CVE-2026-81376

mass1

Security Feature Bypass in Microsoft Visual Studio Code

CVSS 3.1
9.6 critical
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-81376 is a critical security feature bypass in Microsoft Visual Studio Code caused by an incomplete comparison with missing factors (CWE-1023), resulting in a protection mechanism failure (CWE-693). The flaw is reachable over a network and exploitation requires user interaction (per the CVSS vector), such as inducing a user to act on attacker-controlled content, after which an unprivileged attacker can bypass the affected security check. The changed-scope metric indicates the bypass can cross a component boundary, and the high confidentiality, integrity and availability ratings mean a successful bypass can have serious consequences beyond weakening a single control. Everyone running Visual Studio Code is potentially affected; the available data does not specify the vulnerable version ranges or the fixing release. Exploitation has not been observed: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.7% chance of exploitation in the next 30 days.

What to do: Monitor Microsoft's advisory for the fixed release and update Visual Studio Code as soon as a patched version is published, since no version numbers are available yet. Until then, exercise caution with untrusted files, repositories and prompts (user interaction is part of the attack vector), and prioritize scheduling the update given the 9.6 critical CVSS despite no known exploitation.

Affected
Microsoft Visual Studio Code
Estimated exposure
massTens of millions of users (VS Code is the most widely used code editor, with roughly 70%+ usage share among professional developers) — Visual Studio Code consistently tops developer usage surveys (about 70-75% usage in Stack Overflow's annual survey), implying a user base in the tens of millions, though the share of users affected by this specific comparison flaw and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-693, CWE-1023
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.