CVE-2026-32203 is a stack-based buffer overflow vulnerability affecting .NET and Visual Studio that allows unauthenticated remote attackers to cause denial of service. The vulnerability can be triggered over a network without requiring user interaction or elevated privileges, making it broadly accessible to potential threat actors. This flaw presents a moderately elevated risk profile with a CVSS score of 7.5 (HIGH severity), though it does not enable data confidentiality or integrity compromise. The vulnerability does not currently appear on the Known Exploited Vulnerabilities (KEV) catalog and is not listed as actively exploited in the wild, indicating limited real-world attack activity at present. Community attention remains minimal, as evidenced by the low EPSS score of 0.00118, suggesting this vulnerability is not yet a significant exploitation vector compared to other known security flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.0.6CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.26CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.15CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 17.12.0, < 17.12.19CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.14.0, < 17.14.30CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.