NCSC-2026-0285 [1.00] [M/H] Vulnerabilities patched in Microsoft Developer Tools
Microsoft has patched vulnerabilities in various Developer Tools. An attacker can exploit the vulnerabilities to conduct attacks that may result in the damage categories listed in the table below. Successful exploitation requires the attacker to trick the victim into importing and processing a malicious source code file.
Visual Studio Code CoPilot Chat Extension: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65675 | 7.10 | Security feature bypass | |----------------|------|-------------------------------------| Microsoft PowerShell Core: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-58612 | 7.40 | Access to sensitive data | | CVE-2026-70337 | 8.80 | Arbitrary code execution | |----------------|------|-------------------------------------| GitHub Copilot and Visual Studio Code: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-70335 | 7.80 | Privilege escalation | |----------------|------|-------------------------------------| Visual Studio Code: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-58650 | 7.80 | Security feature bypass | | CVE-2026-59113 | 8.80 | Arbitrary code execution | | CVE-2026-47285 | 6.50 | Access to sensitive data | | CVE-2026-69320 | 8.80 | Arbitrary code execution | | CVE-2026-69278 | 7.80 | Security feature bypass | | CVE-2026-69306 | 8.20 | Security feature bypass | | CVE-2026-70336 | 8.80 | Arbitrary code execution | |----------------|------|--
CSIRTS triage
- What
- Vulnerabilities in Visual Studio Code CoPilot Chat Extension and Microsoft PowerShell Core allow security feature bypass and unauthorized data access.
- Who is affected
- Users of Visual Studio Code with CoPilot Chat Extension and Microsoft PowerShell Core are affected; exploitation requires processing malicious source code.
- Urgency
- Moderate-to-high—CVSS scores range from 7.1 to 8.8 and exploitation requires social engineering.
- Action
- Apply patches to Visual Studio Code CoPilot Chat Extension and PowerShell Core as available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Developer Tools
Get an email when a new Developer Tools advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0285
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-656750.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-586120.80% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703370.76% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703350.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-586500.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-591130.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-472850.89% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-693200.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-692780.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-693060.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft products (August 12, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft .Net (August 12, 2026)cert-fr-avis
- mediumGHSA-9mrh-pw7c-9mqm: Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerabilityghsa
- highGHSA-vg44-h755-9hw7: Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerabilityghsa
- highGHSA-fx4q-gjrx-2jw6: Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerabilityghsa
- highGHSA-gg8c-3338-xw2f: Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerabilit…ghsa
- mediumGHSA-9mr8-pwpw-3j2w: Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerabilityghsa
- highGHSA-jqhp-238x-qhgf: Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerabilityghsa
- highGHSA-m93f-wj8c-rp8p: Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerabilityghsa
- mediumGHSA-r6mh-95jw-g7qg: Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerabilityghsa
- highCVE-2026-70354: Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.nvd
Recent advisories for Microsoft Developer Tools
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilitiescert-bund · 2026-08-14
- high[UPDATE] [high] Microsoft Developer Tools: Multiple Vulnerabilitiescert-bund · 2026-07-28
- unknownNCSC-2026-0235 [1.00] [M/H] Vulnerabilities fixed in Microsoft Developer Toolsncsc-nl · 2026-07-14
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13