Description
Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, gain privileges, obtain sensitive information.
Below is a complete list of vulnerabilities:
- An information disclosure vulnerability in Visual Studio Code can be exploited remotely to obtain sensitive information.
- A security feature bypass vulnerability in Visual Studio Code Python Extension can be exploited remotely to bypass security restrictions.
- An information disclosure vulnerability in PowerShell can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in .NET can be exploited remotely to gain privileges.
- A security feature bypass vulnerability in Visual Studio Code can be exploited remotely to bypass security restrictions.
- A remote code execution vulnerability in Visual Studio Code can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in PowerShell can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in .NET can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in .NET Framework can be exploited remotely to gain privileges.
- A remote code execution vulnerability in .NET Framework can be exploited remotely to execute arbitrary code.
- An information disclosure vulnerability in Microsoft QUIC can be exploited remotely to obtain sensitive information.
- A security feature bypass vulnerability in .NET can be exploited remotely to bypass security restrictions.
- An information disclosure vulnerability in .NET can be exploited remotely to obtain sensitive information.
- A denial of service vulnerability in .NET can be exploited remotely to cause denial of service.
- A security feature bypass vulnerability in CoPilot Chat can be exploited remotely to bypass security restrictions.
- An elevation of privilege vulnerability in GitHub Copilot and Visual Studio Code can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Microsoft PowerShell can be exploited remotely to execute arbitrary code.
- A security feature bypass vulnerability in Microsoft PowerShell can be exploited remotely to bypass security restrictions.
- A remote code execution vulnerability in .NET Core can be exploited remotely to execute arbitrary code.
Original advisories
- CVE-2026-54981
- CVE-2026-58612
- CVE-2026-58641
- CVE-2026-58650
- CVE-2026-59113
- CVE-2026-59119
- CVE-2026-62871
- CVE-2026-62872
- CVE-2026-62886
- CVE-2026-62897
- CVE-2026-62898
- CVE-2026-62899
- CVE-2026-62900
- CVE-2026-62901
- CVE-2026-62902
- CVE-2026-62909
- CVE-2026-65675
- CVE-2026-65810
- CVE-2026-69278
- CVE-2026-69306
- CVE-2026-69320
- CVE-2026-70335
- CVE-2026-70336
- CVE-2026-70337
- CVE-2026-70338
- CVE-2026-70354
Exploitation
Related products
- Microsoft-.NET-Framework
- Microsoft-Visual-Studio
- Microsoft-Windows
- .NET
- PowerShell
- Visual-Studio-Code
- Microsoft-Visual-Studio-Code
CVE list
- CVE-2026-47285 unknown
- CVE-2026-54981 unknown
- CVE-2026-58612 unknown
- CVE-2026-58641 unknown
- CVE-2026-58650 unknown
- CVE-2026-59113 unknown
- CVE-2026-59119 unknown
- CVE-2026-62871 unknown
- CVE-2026-62872 unknown
- CVE-2026-62886 unknown
- CVE-2026-62897 unknown
- CVE-2026-62898 unknown
- CVE-2026-62899 unknown
- CVE-2026-62900 unknown
- CVE-2026-62901 unknown
- CVE-2026-62902 unknown
- CVE-2026-62909 unknown
- CVE-2026-65675 unknown
- CVE-2026-65810 unknown
- CVE-2026-69278 unknown
- CVE-2026-69306 unknown
- CVE-2026-69320 unknown
- CVE-2026-70335 unknown
- CVE-2026-70336 unknown
- CVE-2026-70337 unknown
- CVE-2026-70338 unknown
- CVE-2026-70354 unknown
KB list
- 5120418
- 5120695
- 5120698
- 5120699
- 5120700
- 5120701
- 5120702
- 5120703
- 5120704
- 5120705
- 5120706
- 5120708
- 5120709
- 5120710
- 5120711
- 5120713
- 5120714
- 5120716
- 5120747
- 5122104
- 5122105
- 5122106
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!