NPM · SEPTEMBER 2026 · CONFIRMED

Visual Studio Code Vulnerability CVE-2026-81376: Critical Security Bypass

Severity
CRITICAL
CVSS
9.6
Affected component
visual studio code (npm)
Affected versions
>= 1.136.1, <= 1.136.1 or >= 1.136.0, <= 1.136.0 or >= 1.134.0, <= 1.134.0 or >= 1.16.0, <= 1.16.0 or >= translation/20170331.01, <= translation/20170331.01 or >= translation/20170324.01, <= translation/20170324.01 or >= translation/20170317.01, <= translation/20170317.01 or >= translation/20170311.01, <= translation/20170311.01 or >= translation/20170227.01, <= translation/20170227.01 or >= translation/20170217.01, <= translation/20170217.01 or >= translation/20161209.01, <= translation/20161209.01 or >= translation/20161014.01, <= translation/20161014.01 or >= translation/20160902.01, <= translation/20160902.01 or >= translation/20160826.01, <= translation/20160826.01 or >= translation/20160817.01, <= translation/20160817.01 or >= 1.1.0-insider, <= 1.1.0-insider or >= 0.10.12-insiders, <= 0.10.12-insiders or >= 0.10.10-insiders, <= 0.10.10-insiders or >= 0.10.7-insiders, <= 0.10.7-insiders or >= 0.10.5, <= 0.10.5
Patched version
Not yet available
CVE-2026-81376

A critical vulnerability in Visual Studio Code (CVE-2026-81376) allows unauthorized network security bypass. Users of affected versions should update immediately.

What happened

The vulnerability, tracked as CVE-2026-81376, arises from an incomplete comparison with missing factors in Visual Studio Code. This flaw enables an unauthorized attacker to bypass a security feature over a network. The issue was first flagged on September 8, 2026, and confirmed on September 11, 2026. Affected versions include a wide range from 1.136.1 to 0.10.5 and specific translation versions.

The vulnerability has a CVSS score of 9.6, indicating a critical severity level. Although it has not been exploited in the wild, the potential impact is significant. Users are advised to monitor for patches and update to the latest version of Visual Studio Code as soon as it becomes available.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If visual studio code is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using Visual Studio Code version >= 1.136.1, <= 1.136.1 or >= 1.136.0, <= 1.136.0 or >= 1.134.0, <= 1.134.0 or >= 1.16.0, <= 1.16.0 or any of the specified translation versions.

What should I do right now?

Monitor for patches and update Visual Studio Code to the latest version once available.

When will a patch be released?

The primary sources should be consulted for the latest information on patch releases.

Sources

Join the 0Day waitlist →

← Back to all threats