
Microsoft has released 24 CVEs for its developer tools this month, 23 of which were rated Important and one Critical. Security feature bypasses are the focus, with eight CVEs, remote code execution and information disclosure, four each.
- The only critical entry is CVE-2026-34182 in CVSS 9.1, a bug in CMS AuthEnvelopedData handling that allows forged messages to be accepted. It will reach Visual Studio 2017–2022.
- The highest scoring entry in this family is not critical. CVE-2026-81376, a Visual Studio Code security feature bypass, reaches CVSS 9.6 with an important rating. This is a useful reminder that CVSS severity labels and ratings answer different questions.
- Visual Studio Code and its Copilot extensions accept 10 entries, primarily to bypass security features. Update the editor to ensure that workspace trust requests, extension installations, and remote sessions work as configured.
- .NET provides SDK updates for all three supported lines, x64 and x86: 8.0.131 and 8.0.425, 9.0.121 and 9.0.318, and 10.0.112 and 10.0.401. Install them, then build and run a representative project to check for regressions. While you’re there, keep the .NET release date of November 8 – November 10 in mind.
- The .NET Framework ships monthly rollups for each operating system: Windows Server 2012 (KB5126147), Server 2012 R2 (KB5126148), Windows 10 1809 (KB5126144), 21H2 (KB5126145), 22H2 (KB5126146), and Server 2022 (KB5126149). One gap worth noting is that the 4.7.2 package for Windows 10 1607 is listed as pending and will be released at a later date, so those still using 1607 will not complete their platform update this cycle.
Add them to your standard release schedule along with your Windows, Office, and SQL Server priorities for the month. Keep the November 10th date for .NET 8 and PowerShell 7.4 in mind while you’re in the developer community, as this month’s fix does not apply to any branch.
Adobe (and third party updates)
September is the biggest release of the year, and this (crazy, super large) volume is the least interesting thing about it. The 963 CVEs are of lower significance than the 55 entries that Microsoft flags as high risk, and they are related to printing and fonts. Adobe shipped two builds of Acrobat within one digit of each other, and only the second one is a security update (nothing to worry about here). Of the reissued Microsoft CVEs, 25 are not owned by Microsoft. The version number won’t tell you much about the work ahead. So, given my (top secret knowledge) of how Microsoft will perform over the summer, here’s my prediction for next month (October). It won’t be as big as this month – but wait – November will be big. Let’s increase these numbers (or not).