CVE-2026-63518
Microsoft Office Word Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowThis is a Microsoft Word security flaw that can let an attacker run code when a user opens a specially made document, and you should update right away—especially if your team receives emails with Word files.
CVE-2026-63518 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that can be triggered by a specially crafted Word document to achieve remote code execution in the context of the user opening the file; patches are available for Microsoft 365 apps, Microsoft Office, and multiple Mac Office builds.
What to do now
- Check your Microsoft Word version(s): in Word, go to File → Account → About Word (or Word → About Word on Mac) and note the exact version/build.
- Compare the version/build to the fixed releases:
- Microsoft 365 apps / Microsoft Office: install the latest update(s) from OfficeSecurityReleases.
- Microsoft Office 365 for Mac / Microsoft Office LTSC for Mac 2021 / Microsoft Office LTSC for Mac 2024: update to 16.112.26081010.
- Microsoft Office (Windows) / Office 2019/2021/2024: ensure you’re updated to the Microsoft-provided fixed release from OfficeSecurityReleases.
- Update immediately using Microsoft’s security update guidance for CVE-2026-63518.
- Until everyone is updated, block risky email behavior: treat unexpected Word attachments as unsafe and avoid opening them unless you can verify the sender and content.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-63518 and every CVE in our database. Create a free account — no credit card required.
Create Free Account