CVE-2026-63513
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-63513 is a Microsoft Office bug that can let attackers run malicious code on your computer if you open a specially crafted Office file. Typical small businesses should treat this as serious and patch soon, especially if employees open Office attachments from email.
CVE-2026-63513 is a local, user-assisted Microsoft Office graphics parsing flaw (CWE-122) that can lead to remote code execution when a user opens a specially crafted document; Microsoft 365 Apps and multiple Office products have fixed updates available.
What to do now
- Check which Microsoft Office products and versions are installed on your computers (Windows and macOS).
- Verify whether any devices are running the affected versions (see the fixed versions below in Step 3).
- Update Microsoft Office to the fixed version: Microsoft 365 Apps using the Office security releases; Microsoft Office (Windows) to 16.0.5565.1001; and on Mac to 16.112.26081010 for Microsoft Office 365 for Mac, Office LTSC for Mac 2021, and Office LTSC for Mac 2024.
- If you cannot patch immediately, block or quarantine unsolicited Office attachments and remind staff not to open unexpected files.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-63513 and every CVE in our database. Create a free account — no credit card required.
Create Free Account