CVE-2026-55043
Microsoft PowerPoint Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-55043 is a Microsoft PowerPoint security bug that could let someone run code after convincing a user to open a specially made PowerPoint file; if you run Microsoft Office/PowerPoint, you should patch promptly.
CVE-2026-55043 is a PowerPoint remote code execution issue (CWE-122/CWE-190) caused by a memory corruption condition (heap-based buffer overflow), triggered when handling a crafted PowerPoint document—no public exploit is known, but Microsoft has released fixes for multiple Office and PowerPoint versions.
What to do now
- Check which Microsoft Office/PowerPoint products and versions you use (including Microsoft 365 apps, Office 2019/2021/2024, and any Mac variants like Office 365 for Mac or Office LTSC for Mac).
- Update Microsoft Office/PowerPoint using Microsoft’s Office security updates page referenced by the CVE: https://aka.ms/OfficeSecurityReleases (Windows and applicable Microsoft Office channels).
- On Mac, update PowerPoint/Office to 16.111.26071215 (covers Microsoft Office 365 for Mac, Office LTSC for Mac 2021, and Office LTSC for Mac 2024).
- After updating, verify in PowerPoint “About” that the installed version matches the fixed version for your edition (or that you’re on the patched build via the Office security update release).
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-55043 and every CVE in our database. Create a free account — no credit card required.
Create Free Account