Technology · Microsoft
Microsoft Visual-Studio-Code vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 37 vulnerabilities in Microsoft Visual-Studio-Code: 0 in the last 7 days and 24 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-81383, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 24
- Critical, all time
- 2
- Exploited in the wild
- 0
About Microsoft Visual-Studio-Code
A code editor redefined and optimized for building and debugging modern web and cloud applications.
Latest Microsoft Visual-Studio-Code vulnerabilities
- CVE-2026-81383: Microsoft Visual Studio Code information disclosure via name resolutionhighCVSS 7.4EPSS 0.9%
- CVE-2026-81381: Microsoft Visual Studio Code credential exposure in GitHub CopilotmediumCVSS 6.5EPSS 0.9%
- CVE-2026-81380: GitHub Copilot and Visual Studio Code command injectionmediumCVSS 5.3EPSS 0.6%
- CVE-2026-81379: Microsoft Visual Studio Code security feature bypass via improper failure handlinghighCVSS 8.2EPSS 0.5%
- CVE-2026-81377: Microsoft Visual Studio Code path traversalmediumCVSS 6.5EPSS 0.8%
- CVE-2026-81376: Microsoft Visual Studio Code security feature bypass via incomplete comparisoncriticalCVSS 9.6EPSS 0.8%
- CVE-2026-81357: Microsoft Visual Studio Code server-side request forgeryhighCVSS 8.2EPSS 0.5%
- CVE-2026-81356: Visual Studio Code HTTP request/response smugglinghighCVSS 8.2EPSS 0.5%
- CVE-2026-78462: Microsoft Visual Studio Code authorization bypass in user-controlled keyhighCVSS 8.8EPSS 0.8%
- CVE-2026-78461: Microsoft Visual Studio Code path traversal bypasshighCVSS 7.4EPSS 1.0%
- CVE-2026-70334: Microsoft Visual Studio Code security feature bypasshighCVSS 7.8EPSS 0.5%
- CVE-2026-70336: Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute…highCVSS 8.8EPSS 0.8%
- CVE-2026-70335: Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual…highCVSS 7.8EPSS 0.5%
- CVE-2026-69320: Microsoft Visual Studio Code OS command injectionhighCVSS 8.8EPSS 0.9%
- CVE-2026-69306: Microsoft Visual Studio Code security feature bypasshighCVSS 8.2EPSS 0.5%
- CVE-2026-69278: Microsoft Visual Studio Code authorization bypasshighCVSS 7.8EPSS 0.3%
- CVE-2026-65675: Microsoft Visual Studio Code CoPilot Chat security bypasshighCVSS 7.1EPSS 0.6%
- CVE-2026-58650: Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a…highCVSS 7.8EPSS 0.3%
- CVE-2026-47285: Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an…mediumCVSS 6.5EPSS 0.9%
- CVE-2026-57102: Microsoft Visual Studio Code security feature bypasshighCVSS 8.8
- CVE-2026-57101: Microsoft Visual Studio Code XSS security bypasshighCVSS 7.1
- CVE-2026-50520: Microsoft Visual Studio Code command injectionhighCVSS 8.4
- CVE-2026-47282: Microsoft Visual Studio Code and GitHub Copilot credential disclosuremediumCVSS 6.5
- CVE-2026-45496: Microsoft Visual Studio Code path traversal security bypassmediumCVSS 5.5
- CVE-2026-50519: Microsoft GitHub Copilot and VS Code insecure default information disclosuremediumCVSS 6.5
Most severe Microsoft Visual-Studio-Code vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-81376: Microsoft Visual Studio Code security feature bypass via incomplete comparisoncriticalCVSS 9.6EPSS 0.8%
- CVE-2026-47281: Microsoft Visual Studio Code privilege escalation via improper input validationcriticalCVSS 9.6
- CVE-2026-69320: Microsoft Visual Studio Code OS command injectionhighCVSS 8.8EPSS 0.9%
- CVE-2026-41109: Microsoft Visual Studio and GitHub Copilot Injection VulnerabilityhighCVSS 8.8EPSS 0.9%
- CVE-2026-70336: Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute…highCVSS 8.8EPSS 0.8%
- CVE-2026-78462: Microsoft Visual Studio Code authorization bypass in user-controlled keyhighCVSS 8.8EPSS 0.8%
- CVE-2026-57102: Microsoft Visual Studio Code security feature bypasshighCVSS 8.8
- CVE-2026-41613: Microsoft Visual Studio Code session fixation privilege escalationhighCVSS 8.8
- CVE-2026-50520: Microsoft Visual Studio Code command injectionhighCVSS 8.4
- CVE-2026-45482: Microsoft Visual Studio Code and GitHub Copilot path traversalhighCVSS 8.4
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 5 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 8 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 11 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/visual-studio-code.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft Visual-Studio-Code vulnerabilities", https://junglewise.ai/threats/technologies/visual-studio-code, 26 September 2026.