Microsoft has addressed 24 Common Vulnerabilities and Exposures (CVEs) in its developer tooling, with 23 classified as important and one as critical. The critical entry, CVE-2026-34182, has a CVSS score of 9.1 and affects CMS AuthEnvelopedData processing in Visual Studio versions 2017 to 2022. The highest-scoring entry is CVE-2026-81376, a security feature bypass in Visual Studio Code, with a CVSS score of 9.6. Visual Studio Code and its Copilot extensions account for ten of the CVEs, primarily related to security feature bypasses. The .NET framework has updates for SDK versions 8.0.131, 8.0.425, 9.0.121, 9.0.318, 10.0.112, and 10.0.401. Monthly rollups for the .NET Framework have been released for various operating systems, including Windows Server 2012 and Windows 10 versions. Adobe has released 963 CVEs, with 55 flagged by Microsoft as high risk, primarily in printing and fonts.