CVE-2026-50467
Microsoft Office Remote Code Execution Vulnerability
Description
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowThis is a Microsoft Office flaw that could let an attacker run code on your computer by tricking a user into opening a specially crafted file, so most small businesses should act now and update Office to the fixed versions.
CVE-2026-50467 is a use-after-free (CWE-416) flaw in Microsoft Office that enables remote code execution when an attacker delivers a malicious document and a user opens it (requires user interaction).
What to do now
- Check which Microsoft Office products and exact versions you have installed (Windows: “File → Account” and “About Office”; Mac: “Word/Excel → About Microsoft Office”).
- If your Office matches any listed product, update to the fixed version for that product:
- For “microsoft 365 apps” update using Microsoft Office security updates (fixed in https://aka.ms/OfficeSecurityReleases).
- For “microsoft office” update to version 16.0.5561.1000.
- For Microsoft Office 365 for Mac and Microsoft Office LTSC for Mac 2021 and 2024 update to 16.111.26071215.
- After updating, verify the “About”/version screen shows the fixed build, and then remove/avoid the suspicious documents you received from untrusted sources.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-50467 and every CVE in our database. Create a free account — no credit card required.
Create Free Account