Skip to main content

CVE-2026-57102

Visual Studio Code Security Feature Bypass vulnerability

Microsoft

MSRC advisory July 14, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-57102
Affected products
Visual Studio Code Security Feature Bypass · Microsoft Visual Studio Code Security Feature Bypass · Microsoft

What happened

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

What it means for your business

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-57102) was added to Microsoft’s security update guidance. Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Sources

Related briefs

Microsoft MSRC

CVE-2026-50376

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-50376) was added to Microsoft’s security update guidance. Acknowledgment updated If you need help checking exposure, call (864) 335-9223.

LowMicrosoft MSRC

CVE-2026-84359

Information leak in Skia in Microsoft Edge vulnerability

Information leak in Skia in Microsoft Edge vulnerability (CVE-2026-84359) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84358

Improper privilege management in Downloads in Microsoft Edge vulnerability

Improper privilege management in Downloads in Microsoft Edge vulnerability (CVE-2026-84358) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-84357

Improper input validation in Omnibox in Microsoft Edge vulnerability

Improper input validation in Omnibox in Microsoft Edge vulnerability (CVE-2026-84357) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.