References https://thehackernews.com/2026/02/critical-flaws-found-in-four-vs-code.html https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-the-remote-code-execution-vulnerability-in-visual-studio-2015-update-3-february-11-2025-kb5049688-8160a890-cbed-4e96-88cd-33699b39b6f5 https://www.sentinelone.com/vulnerability-database/cve-2025-30399/ https://stack.watch/product/microsoft/visual-studio/ https://devblogs.microsoft.com/dotnet/dotnet-10-0-7-oob-security-update/ https://msrc.microsoft.com/update-guide/vulnerability https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-security-updates-for-critical-aspnet-flaw/ https://avd.aliyun.com/detail?id=AVD-2022-24512 https://www.knowsafe.com/ti/info/0/1000525 https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-march-2026-servicing-updates/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)北京中科聚网一体化运营平台 /manage/tplresource/importVisualModuleImg 文件上传漏洞时空智友ERP系统 /formservice updater.uploadStudioFile 文件上传漏洞PoCCVE-2025-25296: Label Studio < 1.16.0 - Cross-Site ScriptingPoCCVE-2025-47783: Label Studio < 1.18.0 - Reflected XSSLabel Studio存在XSS漏洞(CVE-2025-25296)PoCsupabase-studio-exposure: Supabase Studio - ExposurePoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2024-14015: Studiocart <= 2.9.0 - Cross-Site Scripting