{"schema_version":1,"title":"Microsoft Visual Studio 2022 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in Microsoft Visual Studio 2022: 0 in the last 7 days and 13 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-71328, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/visual-studio-2022","json_url":"https://junglewise.ai/threats/technologies/visual-studio-2022.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/visual-studio-2022","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":17,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":1,"last_90_days":13,"last_365_days":15},"latest":[{"cve":"CVE-2026-71328","cvss":8.8,"epss":0.0076,"slug":"cve-2026-71328-microsoft-diasymreader-native-heap-buffer-overflow","title":"Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:12.16+00:00","url":"https://junglewise.ai/threats/cve-2026-71328-microsoft-diasymreader-native-heap-buffer-overflow"},{"cve":"CVE-2026-62909","cvss":7.8,"epss":0.0026,"slug":"cve-2026-62909-microsoft-net-privilege-escalation-in-diagnostics-ipc","title":"Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.","severity":"high","exploited":false,"published_at":"2026-08-11T17:18:44.817+00:00","url":"https://junglewise.ai/threats/cve-2026-62909-microsoft-net-privilege-escalation-in-diagnostics-ipc"},{"cve":"CVE-2026-62902","cvss":6.5,"epss":0.0087,"slug":"cve-2026-62902-microsoft-net-wpf-information-disclosure-in-document-parsing","title":"Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.","severity":"medium","exploited":false,"published_at":"2026-08-11T17:18:44.503+00:00","url":"https://junglewise.ai/threats/cve-2026-62902-microsoft-net-wpf-information-disclosure-in-document-parsing"},{"cve":"CVE-2026-50659","cvss":6.5,"epss":0.0074,"slug":"cve-2026-50659-microsoft-net-and-visual-studio-spoofing-vulnerability","title":"Microsoft .NET and Visual Studio spoofing vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-14T20:17:38.917+00:00","url":"https://junglewise.ai/threats/cve-2026-50659-microsoft-net-and-visual-studio-spoofing-vulnerability"},{"cve":"CVE-2026-50649","cvss":7.8,"slug":"cve-2026-50649-microsoft-net-and-visual-studio-deserialization-remote-code","title":"Microsoft .NET and Visual Studio deserialization remote code execution","severity":"high","exploited":false,"published_at":"2026-07-14T20:17:38.103+00:00","url":"https://junglewise.ai/threats/cve-2026-50649-microsoft-net-and-visual-studio-deserialization-remote-code"},{"cve":"CVE-2026-50528","cvss":8.2,"epss":0.0061,"slug":"cve-2026-50528-microsoft-net-incorrect-authorization-security-bypass","title":"Microsoft .NET incorrect authorization security bypass","severity":"high","exploited":false,"published_at":"2026-07-14T20:17:37.533+00:00","url":"https://junglewise.ai/threats/cve-2026-50528-microsoft-net-incorrect-authorization-security-bypass"},{"cve":"CVE-2026-50526","cvss":7,"epss":0.0022,"slug":"cve-2026-50526-microsoft-net-link-following-tampering-vulnerability","title":"Microsoft .NET link following tampering vulnerability","severity":"high","exploited":false,"published_at":"2026-07-14T20:17:37.24+00:00","url":"https://junglewise.ai/threats/cve-2026-50526-microsoft-net-link-following-tampering-vulnerability"},{"cve":"CVE-2026-50525","cvss":7.5,"epss":0.0117,"slug":"cve-2026-50525-microsoft-net-resource-exhaustion-denial-of-service","title":"Microsoft .NET resource exhaustion denial of service","severity":"high","exploited":false,"published_at":"2026-07-14T20:17:37.12+00:00","url":"https://junglewise.ai/threats/cve-2026-50525-microsoft-net-resource-exhaustion-denial-of-service"},{"cve":"CVE-2026-50524","cvss":7.5,"epss":0.0123,"slug":"cve-2026-50524-microsoft-net-framework-denial-of-service-via-improper-input","title":"Microsoft .NET Framework denial of service via improper input validation","severity":"high","exploited":false,"published_at":"2026-07-14T20:17:37+00:00","url":"https://junglewise.ai/threats/cve-2026-50524-microsoft-net-framework-denial-of-service-via-improper-input"},{"cve":"CVE-2026-47305","cvss":7.8,"slug":"cve-2026-47305-microsoft-visual-studio-protection-mechanism-failure-local-code","title":"Microsoft Visual Studio protection mechanism failure local code execution","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.97+00:00","url":"https://junglewise.ai/threats/cve-2026-47305-microsoft-visual-studio-protection-mechanism-failure-local-code"},{"cve":"CVE-2026-47304","cvss":8.1,"epss":0.0029,"slug":"cve-2026-47304-microsoft-net-improper-cryptographic-signature-verification","title":"Microsoft .NET improper cryptographic signature verification","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.83+00:00","url":"https://junglewise.ai/threats/cve-2026-47304-microsoft-net-improper-cryptographic-signature-verification"},{"cve":"CVE-2026-47303","cvss":8.8,"epss":0.0084,"slug":"cve-2026-47303-microsoft-asp-net-core-authentication-bypass-and-privilege","title":"Microsoft ASP.NET Core authentication bypass and privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.707+00:00","url":"https://junglewise.ai/threats/cve-2026-47303-microsoft-asp-net-core-authentication-bypass-and-privilege"},{"cve":"CVE-2026-47300","cvss":8.8,"epss":0.0078,"slug":"cve-2026-47300-microsoft-asp-net-core-privilege-escalation-in-authentication","title":"Microsoft ASP.NET Core privilege escalation in authentication algorithm","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.303+00:00","url":"https://junglewise.ai/threats/cve-2026-47300-microsoft-asp-net-core-privilege-escalation-in-authentication"},{"cve":"CVE-2026-32177","cvss":7.3,"epss":0.0043,"slug":"cve-2026-32177-microsoft-net-heap-buffer-overflow-privilege-escalation","title":"Microsoft .NET heap buffer overflow privilege escalation","severity":"high","exploited":false,"published_at":"2026-05-12T18:16:58.947+00:00","url":"https://junglewise.ai/threats/cve-2026-32177-microsoft-net-heap-buffer-overflow-privilege-escalation"},{"cve":"CVE-2026-32175","cvss":7.5,"epss":0.0064,"slug":"cve-2026-32175-microsoft-net-core-path-traversal-tampering-vulnerability","title":"Microsoft .NET Core path traversal tampering vulnerability","severity":"high","exploited":false,"published_at":"2026-05-12T18:16:58.737+00:00","url":"https://junglewise.ai/threats/cve-2026-32175-microsoft-net-core-path-traversal-tampering-vulnerability"},{"cve":"CVE-2023-38180","cvss":3.1,"epss":0.1402,"slug":"cve-2023-38180-microsoft-net-core-and-visual-studio-denial-of-service","title":".NET Denial of Service Vulnerability","severity":"critical","exploited":true,"published_at":"2023-08-09T12:56:43+00:00","url":"https://junglewise.ai/threats/cve-2023-38180-microsoft-net-core-and-visual-studio-denial-of-service"},{"cve":"CVE-2022-24464","cvss":7.5,"epss":0.0355,"slug":"cve-2022-24464-microsoft-net-denial-of-service-in-http-form-parsing","title":"Microsoft .NET denial of service in HTTP form parsing","severity":"high","exploited":false,"published_at":"2022-10-21T20:32:34+00:00","url":"https://junglewise.ai/threats/cve-2022-24464-microsoft-net-denial-of-service-in-http-form-parsing"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":977,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":168,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"}],"technology":{"hub":true,"name":"Microsoft Visual Studio 2022","slug":"visual-studio-2022","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":[],"category":"ide","homepage":"https://visualstudio.microsoft.com/","repo_url":"https://github.com/microsoft/visualstudio","description":"An integrated development environment for building applications on Windows, macOS, and cloud platforms.","url":"https://junglewise.ai/threats/technologies/visual-studio-2022"},"most_severe":[{"cve":"CVE-2023-38180","cvss":3.1,"epss":0.1402,"slug":"cve-2023-38180-microsoft-net-core-and-visual-studio-denial-of-service","title":".NET Denial of Service Vulnerability","severity":"critical","exploited":true,"published_at":"2023-08-09T12:56:43+00:00","url":"https://junglewise.ai/threats/cve-2023-38180-microsoft-net-core-and-visual-studio-denial-of-service"},{"cve":"CVE-2026-47303","cvss":8.8,"epss":0.0084,"slug":"cve-2026-47303-microsoft-asp-net-core-authentication-bypass-and-privilege","title":"Microsoft ASP.NET Core authentication bypass and privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.707+00:00","url":"https://junglewise.ai/threats/cve-2026-47303-microsoft-asp-net-core-authentication-bypass-and-privilege"},{"cve":"CVE-2026-47300","cvss":8.8,"epss":0.0078,"slug":"cve-2026-47300-microsoft-asp-net-core-privilege-escalation-in-authentication","title":"Microsoft ASP.NET Core privilege escalation in authentication algorithm","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.303+00:00","url":"https://junglewise.ai/threats/cve-2026-47300-microsoft-asp-net-core-privilege-escalation-in-authentication"},{"cve":"CVE-2026-71328","cvss":8.8,"epss":0.0076,"slug":"cve-2026-71328-microsoft-diasymreader-native-heap-buffer-overflow","title":"Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:12.16+00:00","url":"https://junglewise.ai/threats/cve-2026-71328-microsoft-diasymreader-native-heap-buffer-overflow"},{"cve":"CVE-2026-50528","cvss":8.2,"epss":0.0061,"slug":"cve-2026-50528-microsoft-net-incorrect-authorization-security-bypass","title":"Microsoft .NET incorrect authorization security bypass","severity":"high","exploited":false,"published_at":"2026-07-14T20:17:37.533+00:00","url":"https://junglewise.ai/threats/cve-2026-50528-microsoft-net-incorrect-authorization-security-bypass"},{"cve":"CVE-2026-47304","cvss":8.1,"epss":0.0029,"slug":"cve-2026-47304-microsoft-net-improper-cryptographic-signature-verification","title":"Microsoft .NET improper cryptographic signature verification","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.83+00:00","url":"https://junglewise.ai/threats/cve-2026-47304-microsoft-net-improper-cryptographic-signature-verification"},{"cve":"CVE-2026-62909","cvss":7.8,"epss":0.0026,"slug":"cve-2026-62909-microsoft-net-privilege-escalation-in-diagnostics-ipc","title":"Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.","severity":"high","exploited":false,"published_at":"2026-08-11T17:18:44.817+00:00","url":"https://junglewise.ai/threats/cve-2026-62909-microsoft-net-privilege-escalation-in-diagnostics-ipc"},{"cve":"CVE-2026-50649","cvss":7.8,"slug":"cve-2026-50649-microsoft-net-and-visual-studio-deserialization-remote-code","title":"Microsoft .NET and Visual Studio deserialization remote code execution","severity":"high","exploited":false,"published_at":"2026-07-14T20:17:38.103+00:00","url":"https://junglewise.ai/threats/cve-2026-50649-microsoft-net-and-visual-studio-deserialization-remote-code"},{"cve":"CVE-2026-47305","cvss":7.8,"slug":"cve-2026-47305-microsoft-visual-studio-protection-mechanism-failure-local-code","title":"Microsoft Visual Studio protection mechanism failure local code execution","severity":"high","exploited":false,"published_at":"2026-07-14T19:17:08.97+00:00","url":"https://junglewise.ai/threats/cve-2026-47305-microsoft-visual-studio-protection-mechanism-failure-local-code"},{"cve":"CVE-2022-24464","cvss":7.5,"epss":0.0355,"slug":"cve-2022-24464-microsoft-net-denial-of-service-in-http-form-parsing","title":"Microsoft .NET denial of service in HTTP form parsing","severity":"high","exploited":false,"published_at":"2022-10-21T20:32:34+00:00","url":"https://junglewise.ai/threats/cve-2022-24464-microsoft-net-denial-of-service-in-http-form-parsing"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}