CVE-2026-69805: Microsoft Microsoft.diagnostics.runtime
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
Affected products
- Microsoft Microsoft.diagnostics.runtime: before 4.1.740301 (fixed in 4.1.740301)
- Microsoft Visual Studio 2022: from 17.14.0, before 17.14.40 (fixed in 17.14.40)
- Microsoft Visual Studio 2026: from 18.9.0, before 18.9.3 (fixed in 18.9.3)
Published 2026-09-08. Last modified 2026-09-29.