NUGET · SEPTEMBER 2026 · CONFIRMED

Visual Studio Buffer Overflow Vulnerability: Critical Security Alert

Severity
HIGH
Affected component
visual studio (nuget)
Patched version
Not yet available
CVE-2026-69522GHSA-2J8R-3C22-8565GHSA-Q72M-F2R4-W4CW

A critical heap-based buffer overflow vulnerability in Visual Studio enables unauthorized remote code execution. Users of Visual Studio are advised to monitor for updates.

What happened

A high severity vulnerability, tracked as CVE-2026-69522 and GHSA-2j8r-3c22-8565, has been confirmed in Visual Studio. This vulnerability allows an unauthorized attacker to execute code over a network due to a heap-based buffer overflow. The advisory for this vulnerability has been withdrawn as it is a duplicate of GHSA-2j8r-3c22-8565. Users should refer to the original advisory for further details and patches.

The vulnerability was first flagged on 2026-09-08T18:32:43+00:00 and confirmed on 2026-09-08T22:12:17.086626+00:00. It has not been exploited in the wild as of the latest reports. The affected component is Visual Studio, though no authoritative version range has been published yet.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If visual studio is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Visual Studio, you may be affected. Consult the original advisory GHSA-2j8r-3c22-8565 for more information.

What should I do right now?

Monitor the original advisory GHSA-2j8r-3c22-8565 for further details and patches. Stay informed about updates from trusted sources.

Is there a patch available?

No official fix has been published yet. Monitor the sources for updates.

How can I protect my network from this vulnerability?

Implement network security measures to mitigate the risk of remote code execution and review your incident response plan.

Sources

Join the 0Day waitlist →

← Back to all threats