CVE-2026-59113Disclosure(microsoft / visual_studio_code)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft visual_studio_code systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • visual_studio_code

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
visual_studio_code

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-11: 1Mentions · 2026-09-03: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 1Technical Details · 2026-09-03: 108-1109-03
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-111
Disclosure1
2026-09-031
General1
Full discourse2 posts
  • connect24h@connect24h
    General

    VS Codeで9件同時は、さすがに背筋が冷える。 MSRC上ではRCE 3件(CVE-2026-59113、69320、70336)のほか、Security Feature Bypass、Information Disclosure、Elevation of Privilegeが並び、Copilot ChatもCVE-2026-65675と70335で射程に入るとされている。 ただし、こちらではMSRC本文を取得できず、影響versionや攻撃条件は未検証。騒ぐより先に、端末管理台帳でVS Code本体の実version、更新channel、Copilot Chat導入有無を突合できるかがCSIRTの分かれ目になる。開発端末はコードを書く場所であると同時に、権限と秘密情報が集まる場所だ。9件それぞれのaffected packageと成立条件は元情報で追いたい。 便利な開発環境ほど、攻撃面も一緒に育つ。 ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58650

    Post summary

    The notice highlights up to nine VS Code vulnerabilities, describing their categories (RCE, privilege elevation, etc.) but provides no PoC, exploit code, or patch information, urging CSIRT to verify affected packages and conditions.

    00041576
    7.6K followersView on X
  • Windows Forum@windowsforum
    Disclosure

    ⚠️ Microsoft disclosed a VS Code remote-code flaw while keeping the fix details under wraps. Update anyway—Workspace Trust isn’t a vulnerability patch, no matter how comforting the checkbox feels. https://windowsforum.com/security-alerts.84/cve-2026-59113-update-vs-code-despite-missing-fix-details.442494/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsSecurity #RemoteCodeExecution #VisualStudioCode https://t.co/cCyhGx6sKe

    Post summary

    Microsoft disclosed CVE‑2026‑59113, a remote code execution flaw in VS Code, but withheld fix details; users are urged to update regardless, with Workspace Trust not being a mitigation.

    0000050
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftvisual_studio_code---

Explore more