CVE-2026-40376
An attacker can exploit multiple vulnerabilities in Microsoft Visual Studio Code, Microsoft ASP.NET, Microsoft .NET, and Microsoft Visual Studio 2026 to gain administrative privileges, manipulate data, disclose confidential information, or bypass authentication.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Developer Tools can be exploited for various attacks.
- Who is affected
- Users of Microsoft Developer Tools are affected.
- Urgency
- Remediation is important due to the potential for serious security breaches.
- Action
- Update Microsoft Developer Tools to the latest version to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-40376
Get an email if CVE-2026-40376 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
Advisory coverage (2)
- high[UPDATE] [high] Microsoft DeveloperTools: Multiple vulnerabilitiescert-bund · 2026-07-17
- highCVE-2026-40376: Visual Studio Code Elevation of Privilege Vulnerabilitymsrc · 2026-06-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-40376)