NCSC-2026-0235 [1.00] [M/H] Vulnerabilities fixed in Microsoft Developer Tools
Microsoft has fixed vulnerabilities in Developer Tools such as .NET and Visual Studio. An attacker can exploit the vulnerabilities to carry out attacks that can lead to damage in the categories mentioned in the attached table. For successful exploitation, the attacker must deceive the victim into opening and processing a malicious source file in the development environment.
CSIRTS triage
- What
- Vulnerabilities in Developer Tools can lead to various attacks if a victim processes a malicious source file.
- Who is affected
- Users of Microsoft Developer Tools such as .NET and Visual Studio.
- Urgency
- Remediation is necessary as these vulnerabilities could lead to significant impacts, although no exploitation has been reported.
- Action
- Update Microsoft Developer Tools to the latest version to mitigate the vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Developer Tools
Get an email when a new Developer Tools advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0235
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-473050.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-472820.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all scored CVEs.
- Low exploitation riskCVE-2026-454960.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-505200.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-571010.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-571020.77% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
- Low exploitation riskCVE-2026-505240.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all scored CVEs.
- Low exploitation riskCVE-2026-505270.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all scored CVEs.
- Low exploitation riskCVE-2026-506460.95% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all scored CVEs.
- Low exploitation riskCVE-2026-506480.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Microsoft Developer Tools: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Microsoft DeveloperTools: Multiple vulnerabilitiescert-bund
- highGHSA-j8gr-8fp3-5q5h: Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerabilityghsa
- highGHSA-55jh-fwmh-39m4: Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerabilityghsa
- highGHSA-8prm-248r-h957: Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerabilityghsa
- highGHSA-2p3q-h3hg-jcqq: Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerabilityghsa
- highGHSA-mmjf-rqrv-855v: Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerabilityghsa
- highGHSA-2969-4q4w-w5h3: Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerabilityghsa
- highGHSA-wp74-jgxh-gv4q: Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerabilityghsa
- mediumGHSA-74jp-vm22-8q8x: Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerabilityghsa
- highGHSA-8q5v-6pqq-x66h: Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerabilityghsa
- highGHSA-qvw7-jm5c-6hqw: Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerabilityghsa
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30