Microsoft Security Response Center guidance
Release Notes
Vendor-listed releases
- 0.37.1
- 1.110.1
Vulnerability intelligence
CVE-2026-21523 and is rated High severity with a CVSS score of 8.0. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.