CVE-2026-58650General(microsoft / visual_studio_code)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • visual_studio_code

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
visual_studio_code

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-11: 1Mentions · 2026-09-03: 1Technical Details · 2026-09-03: 108-1109-03
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • connect24h@connect24h
    General

    VS Codeで9件同時は、さすがに背筋が冷える。 MSRC上ではRCE 3件(CVE-2026-59113、69320、70336)のほか、Security Feature Bypass、Information Disclosure、Elevation of Privilegeが並び、Copilot ChatもCVE-2026-65675と70335で射程に入るとされている。 ただし、こちらではMSRC本文を取得できず、影響versionや攻撃条件は未検証。騒ぐより先に、端末管理台帳でVS Code本体の実version、更新channel、Copilot Chat導入有無を突合できるかがCSIRTの分かれ目になる。開発端末はコードを書く場所であると同時に、権限と秘密情報が集まる場所だ。9件それぞれのaffected packageと成立条件は元情報で追いたい。 便利な開発環境ほど、攻撃面も一緒に育つ。 ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58650

    Post summary

    The post highlights nine VS Code CVEs with their types but provides no PoC, exploit code, or patch info—only a recommendation to check local installations.

    00041576
    7.6K followersView on X
  • Windows Forum@windowsforum
    General

    🛡️ Microsoft disclosed a VS Code bypass with no fixed version or exposure boundary. Translation: inventory everything, patch nothing confidently, and wait for the missing half of the advisory. https://windowsforum.com/security-alerts.84/cve-2026-58650-vs-code-bypass-no-fixed-version-yet.442475/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VulnerabilityManagement #PatchManagement #VisualStudioCode https://t.co/CNXD3mZMAK

    Post summary

    The post announces a Microsoft VS Code bypass vulnerability (CVE-2026-58650) but lacks substantive details about exploitation, patches, or technical specifics, making it a high‑level advisory.

    0000037
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftvisual_studio_code---

Explore more