CVE-2026-62822
Windows GDI+ Remote Code Execution Vulnerability
Description
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-62822 is a Windows bug where attackers can send specially crafted network data to trigger code to run on your machine; if you have Internet-facing exposure and can be tricked into viewing/processing the malicious content, you should treat this as a serious patch-now issue.
CVE-2026-62822 is a Windows GDI+ Remote Code Execution vulnerability (CWE-122/CWE-190) where network-delivered malicious content triggers an integer error in Windows GDI+, leading to remote code execution without authentication; user interaction is required.
What to do now
- Check which Windows version you run (Windows 10/11 or Windows Server 2012/2012 R2/2016/2019/2022/2025) and confirm your current build number.
- Apply the Microsoft security update for CVE-2026-62822 to reach the fixed build listed below for your exact edition.
- If you cannot patch right away, reduce exposure by limiting who can reach Windows components from the network and block untrusted content sources until updates are installed.
- After updating, verify the update is installed and review relevant system/app logs for GDI+ related errors around the time of any suspicious activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62822 and every CVE in our database. Create a free account — no credit card required.
Create Free Account