CVE-2026-50650
An attacker can exploit multiple vulnerabilities in Microsoft Visual Studio Code, .NET Framework, Microsoft .NET, Visual Studio 2022, and Visual Studio 2026 to gain elevated permissions, including administrative rights, execute arbitrary code, bypass security measures, manipulate or disclose data, trigger a Denial-of-Service state, or conduct spoofing attacks.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Developer Tools can be exploited to gain elevated permissions and execute arbitrary code.
- Who is affected
- Users of Microsoft Visual Studio Code, .NET Framework, and Visual Studio are affected.
- Urgency
- Remediation is high priority due to the potential for significant impact.
- Action
- Update to the latest versions of Microsoft Developer Tools.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-50650
Get an email if CVE-2026-50650 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Advisory coverage (7)
- high[NEW] [high] Microsoft DeveloperTools: Multiple vulnerabilitiescert-bund · 2026-07-23
- highGHSA-2969-4q4w-w5h3: Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerabilityghsa · 2026-07-21
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis · 2026-07-15
- unknownMultiple vulnerabilities in Microsoft .Net (July 15, 2026)cert-fr-avis · 2026-07-15
- highCVE-2026-50650: Improper control of generation of code ('code injection') in .NET Framework allows an unauthor…nvd · 2026-07-14
- unknownNCSC-2026-0235 [1.00] [M/H] Vulnerabilities fixed in Microsoft Developer Toolsncsc-nl · 2026-07-14
- highCVE-2026-50650: .NET Framework Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-50650)