CVE-2026-55033
Microsoft Word Remote Code Execution Vulnerability
Description
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-55033 is a Microsoft Word security flaw that can let someone run code when a user opens a specially crafted document; because it targets common Microsoft Office/Word apps, most small businesses should treat this as urgent and update to the fixed versions.
CVE-2026-55033 is an RCE issue in Microsoft Word related to an integer overflow/wraparound (CWE-122/CWE-190) that can be triggered by opening a crafted document, leading to unauthorized code execution within the Word/Office context on affected Microsoft products.
What to do now
- Check which affected Microsoft products you use (including Word and SharePoint Server) and your exact version/build.
- Update Microsoft 365 Apps / Microsoft Office / Microsoft 365 to the fixed releases listed in https://aka.ms/OfficeSecurityReleases.
- For Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024, upgrade to version 16.111.26071215.
- For Microsoft SharePoint Enterprise Server 2016, upgrade to version 16.0.5561.1001.
- For Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition, upgrade to versions 16.0.10417.20175 and 16.0.19725.20434 respectively (as applicable).
- After updating, confirm the build/version reflects the fixed version; if you can’t update immediately, temporarily restrict opening files from untrusted sources until updates are applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-55033 and every CVE in our database. Create a free account — no credit card required.
Create Free Account