CVE-2026-55129
Microsoft Office Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-55129 is a Microsoft Office flaw that can let an attacker run malicious code through specially crafted Office files; because it’s a remote code execution risk, small businesses should patch soon if you use affected Microsoft Office/ Microsoft 365 versions.
CVE-2026-55129 is a Microsoft Office remote code execution vulnerability (CWE-122) where a crafted Office file can trigger a memory corruption bug in Office, leading to code execution when the file is opened.
What to do now
- Check your Microsoft Office / Microsoft 365 app versions (Windows and/or macOS) in the Office app “About” screen, and compare against the fixed versions listed below.
- Update Microsoft 365 Apps to the patched build from https://aka.ms/OfficeSecurityReleases (install Office updates right away).
- Update Microsoft Office (Windows) to 16.0.5561.1000.
- Update Microsoft Office (macOS) to 16.111.26071215 for: Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024.
- After updating, re-check the “About” version to confirm you’re on the fixed build, and then block/avoid opening unknown Office files until patched.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-55129 and every CVE in our database. Create a free account — no credit card required.
Create Free Account