
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21523 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in GitHub Copilot and Visual Studio (including the Visual Studio Code Copilot Chat extension) that allows an authorized network attacker to execute arbitrary code. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday update. Visual Studio Code versions prior to 1.109.2 are confirmed affected. The vulnerability carries a CVSS v3.1 base score of 8.0 (High) (Microsoft MSRC, BleepingComputer).
The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition), where a resource state is checked at one point in time but used at a later point, allowing an attacker to manipulate the resource in the intervening window. Exploitation maps to CAPEC-29 (Leveraging TOCTOU Race Conditions) and CAPEC-27 (Leveraging Race Conditions via Symbolic Links). An authorized, low-privileged attacker operating over a network can exploit this race condition window to achieve code execution, though user interaction is required as a precondition. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation results in remote code execution with high impact to confidentiality, integrity, and availability on the affected system. An attacker could execute arbitrary code in the context of the affected application, potentially enabling data theft, file modification, or service disruption. The scope is limited to the affected host (unchanged scope), but compromise of a developer workstation running GitHub Copilot or Visual Studio Code could expose source code, credentials, and other sensitive development assets (Microsoft MSRC, Feedly).
Microsoft released a security patch on February 10, 2026, addressing this vulnerability. Users should update Visual Studio Code to version 1.109.2 or later, and ensure the GitHub Copilot and Visual Studio Code Copilot Chat extensions are updated to their latest patched versions. No specific configuration-based workaround has been published; upgrading to the patched version is the recommended and primary remediation action (Microsoft MSRC, Rapid7).
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Krebs on Security, Cisco Talos, Rapid7, and Sophos, though CVE-2026-21523 was not among the most prominently highlighted issues in those updates (which focused on six actively exploited zero-days). Community discussion on social platforms such as Bluesky and Mastodon was limited and primarily aggregated within general Patch Tuesday coverage. No specific researcher commentary or vendor statements beyond the Microsoft advisory have been identified for this CVE (BleepingComputer, Talos, Krebs on Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."