[UPDATE] [high] Microsoft Developer Tools: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Visual Studio, Microsoft Visual Studio Code, Microsoft .NET Framework, and Microsoft .NET to execute arbitrary code, manipulate data, escalate privileges, bypass security measures, disclose information, and conduct a denial of service attack.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in Microsoft Visual Studio, Microsoft Visual Studio Code, Microsoft .NET Framework, and Microsoft .NET to execute arbitrary code, manipulate data, escalate privileges, bypass security measures, disclose information, and conduct a denial of service attack.
- Who is affected
- Users of Microsoft Developer Tools are affected.
- Urgency
- Remediation is urgent due to the high severity and potential for exploitation.
- Action
- Update Microsoft Developer Tools to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Developer Tools
Get an email when a new Developer Tools advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1488
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-321750.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Low exploitation riskCVE-2026-321770.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-354330.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all scored CVEs.
- Low exploitation riskCVE-2026-410940.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all scored CVEs.
- Low exploitation riskCVE-2026-411090.86% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all scored CVEs.
- Low exploitation riskCVE-2026-416100.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2026-416110.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
- Low exploitation riskCVE-2026-416120.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-416130.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all scored CVEs.
- Moderate exploitation riskCVE-2026-428992.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 83% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-32175 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-32177 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35433 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41094 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41109 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41610 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41611 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41612 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41613 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42899 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft DeveloperTools: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0235 [1.00] [M/H] Vulnerabilities fixed in Microsoft Developer Toolsncsc-nl
- highCVE-2026-41109: GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerabilitymsrc
- unknownMultiple vulnerabilities in Tenable Identity Exposure (June 24, 2026)cert-fr-avis
- highGHSA-8x9c-mqxv-q2pp: Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerabilityghsa
- highGHSA-rg75-q538-x34v: Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerabilityghsa
Recent advisories for Microsoft Developer Tools
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0235 [1.00] [M/H] Vulnerabilities fixed in Microsoft Developer Toolsncsc-nl · 2026-07-14
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31