Cyber Resilience

CVE-2026-69306

Microsoft Visual Studio Code ≤ 1.132.1

Published
11 August 2026
Modified
14 August 2026
Patch / advisory
CVSS Score v3.1 8.2
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS Score 0.0040 34th percentile
Risk Priority 58 floored blend · peak EPSS

Summary

CVE-2026-69306 is a high-severity Failing Open (CWE-636) vulnerability in Microsoft Visual Studio Code. Its CVSS base score is 8.2 (High).

Operationally, ranked at the 34th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to CP-12 (Safe Mode) and SC-24 (Fail in Known State) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-43488Same product: Microsoft Visual Studio Code
CVE-2023-29338Same product: Microsoft Visual Studio Code
CVE-2024-26165Same product: Microsoft Visual Studio Code
CVE-2023-33144Same product: Microsoft Visual Studio Code
CVE-2023-21779Same product: Microsoft Visual Studio Code
CVE-2023-24893Same product: Microsoft Visual Studio Code
CVE-2023-36742Same product: Microsoft Visual Studio Code
CVE-2024-43532Same vendor: Microsoft
CVE-2025-21210Same vendor: Microsoft
CVE-2024-43601Same product: Microsoft Visual Studio Code

Affected Assets

microsoft
visual studio code
≤ 1.132.1

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V3.2.1
  • V7.4.1
  • V8.3.3
  • V10.3.4

Mitigating Controls (NIST 800-53 r5) AI

SC-24 directly requires the system to fail to a known state that preserves security properties, structurally stopping fallback to a less-secure mode.

SI-17 mandates explicit fail-safe procedures that activate on indicated failures, preventing the insecure fallback behavior.

CP-12 forces entry into a safe mode on detected conditions, limiting exposure but not covering every failure path.

SA-8 requires application of engineering principles that include fail-secure design, reducing the likelihood the weakness is introduced.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure-development practices explicitly include designing error and failure handling to remain in a secure state.

PR.AA-05 partial match
prevents

Least-privilege policy and enforcement directly counters the permissive-access fallback example in the CWE.

PR.PS-01 partial match
prevents

Hardened baselines and configuration management reduce the chance that error paths default to insecure settings.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

The control forces an explicit evaluation step before any response, reducing the chance that a failure condition will default to an unsafe open state.

References