CVE-2026-69805
Visual Studio 2022 vulnerability analysis and mitigation

Overview

CVE-2026-69805 is an External Control of File Name or Path vulnerability in Microsoft .NET that allows an unauthenticated network attacker to elevate privileges on affected systems, requiring user interaction to exploit. It affects Microsoft Visual Studio 2022 version 17.14 (prior to 17.14.40), Microsoft Visual Studio 2026 version 18.9 (prior to 18.9.3), and Microsoft.Diagnostics.Runtime version 4.1.740301. The vulnerability was disclosed and patched on September 8, 2026, as part of Microsoft's September 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is classified under CWE-73 (External Control of File Name or Path), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), and CWE-522 (Insufficiently Protected Credentials). The vulnerability exists within .NET's handling of file name or path inputs, where externally supplied values are not sufficiently validated or sanitized, enabling an attacker to manipulate file system calls. Exploitation occurs over the network (AV:N) with high attack complexity (AC:H) and requires user interaction (UI:R), but no prior privileges are needed. Associated attack patterns include path manipulation techniques such as URL encoding bypass (CAPEC-64, CAPEC-72, CAPEC-76) and environment variable subversion (CAPEC-13), as well as dynamic linker hijacking (T1574.006) and PATH environment variable interception (T1574.007) (Microsoft MSRC, Feedly).

Impact

Successful exploitation allows an unauthenticated attacker to elevate privileges on the affected system, with high impact to confidentiality, integrity, and availability. An attacker who achieves privilege escalation could access sensitive information, modify system files or configurations, and potentially disrupt service availability. The vulnerability's network attack vector means it can be triggered remotely, increasing the risk of exploitation in environments where affected Visual Studio or .NET Diagnostics Runtime components are exposed (Microsoft MSRC, Feedly).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, consistent with the requirement for user interaction (Feedly).

Mitigation and workarounds

Microsoft released patches on September 8, 2026, as part of the September 2026 Patch Tuesday. Users should update to the following fixed versions: Microsoft Visual Studio 2022 version 17.14.40 or later, Microsoft Visual Studio 2026 version 18.9.3 or later, and Microsoft.Diagnostics.Runtime version 4.1.740301 (patched build). Where immediate patching is not possible, restrict network access to systems running vulnerable versions and implement additional access controls to limit exposure. Monitor for suspicious file path manipulation activity as a compensating control (Microsoft MSRC, .NET Blog).

Community reactions

The vulnerability was covered as part of broader September 2026 Patch Tuesday reporting. BleepingComputer reported on the patch cycle, which addressed 966 flaws and 2 zero-days in total. The Zero Day Initiative (ZDI) published its monthly security update review covering this and other September 2026 patches. Rapid7 also included CVE-2026-69805 in its Patch Tuesday analysis (BleepingComputer, ZDI, Rapid7).

Additional resources


SourceThis report was generated using AI

Related Visual Studio 2022 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71328HIGH8.8
  • C# logoC#
  • Microsoft.DiaSymReader.Native
NoYesSep 08, 2026
CVE-2026-69522HIGH8.8
  • C# logoC#
  • dotnet10-runtime
NoYesSep 08, 2026
CVE-2026-69439HIGH8.8
  • C# logoC#
  • dotnet10-runtime
NoYesSep 08, 2026
CVE-2026-69805HIGH7.5
  • Visual Studio 2022 logoVisual Studio 2022
  • cpe:2.3:a:microsoft:visual_studio_2022
NoYesSep 08, 2026
CVE-2026-69806HIGH7
  • Visual Studio 2022 logoVisual Studio 2022
  • dotnet-sdk-10.0
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management