Real-time CVE monitoring

CVE alerts for
VS Code

CVEye scans every new CVE and notifies your team the moment VS Code is affected — before attackers can exploit it.

Monitor VS Code free →No credit card · 7-day trial

Recent VS Code CVEs

  • CVE-2026-83711CRITICALCVSS 10.0

    Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70178HIGHCVSS 8.5

    Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62916CRITICALCVSS 9.1

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62906HIGHCVSS 7.4

    Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-84967MEDIUMCVSS 4.3

    A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades a developer to accept a user-supplied connection target, and then to open the extension's shell feature, can place characters of the unauthorized-user’s choosing into that command line. No privileges on the developer's machine are required, but several user actions are. The confirmation the developer sees does not display the supplied text.

  • CVE-2026-84672HIGHCVSS 8.8

    Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.

  • CVE-2026-19475MEDIUMCVSS 6.5

    An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

Never miss a VS Code vulnerability

CVEye monitors VS Code and your entire stack 24/7, sending instant alerts via email, Slack, Discord, or webhook the moment a new CVE is published.

7-day free trial · No credit card required

Also monitor