CVE-2026-55120
Microsoft PowerPoint Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-55120 is a Microsoft PowerPoint bug that can let an attacker run code on your computer when you open a crafted Office file; this is serious enough that most businesses should update even if you haven’t seen attacks.
Microsoft PowerPoint (part of Microsoft Office/Microsoft 365) has a memory-corruption flaw (CWE-122) that can be triggered by opening a specially crafted file, leading to remote code execution on the victim machine.
What to do now
- Check which affected Microsoft products and versions you run (especially PowerPoint variants listed for Office/Office 365 and for Mac, plus PowerPoint 2016).
- Update Microsoft 365 apps / Microsoft Office using the official Office security updates page until you’re on the fixed release for CVE-2026-55120 (see https://aka.ms/OfficeSecurityReleases).
- For Microsoft Office 365 for Mac and Microsoft Office LTSC for Mac, upgrade to version 16.111.26071215 (includes both LTSC 2021 and LTSC 2024).
- For Microsoft PowerPoint 2016 (Windows), upgrade to 16.0.5561.1000.
- If you cannot update immediately, stop opening files from unknown/untrusted sources and have IT enforce safer attachment/file handling until patching is complete.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-55120 and every CVE in our database. Create a free account — no credit card required.
Create Free Account