CVE-2026-69805: Microsoft Microsoft.diagnostics.runtime

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.

Affected products

  • Microsoft Microsoft.diagnostics.runtime: before 4.1.740301 (fixed in 4.1.740301)
  • Microsoft Visual Studio 2022: from 17.14.0, before 17.14.40 (fixed in 17.14.40)
  • Microsoft Visual Studio 2026: from 18.9.0, before 18.9.3 (fixed in 18.9.3)

Published 2026-09-08. Last modified 2026-09-29.