CVE-2026-63519
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowThis is a Microsoft Office “memory crash” bug that can let an attacker run code on your computer if you open a specially crafted file; small businesses should treat it as urgent and patch Office as soon as possible.
CVE-2026-63519 is a local remote-code-execution flaw (CWE-122) in the Microsoft Office graphics component that can be triggered by user interaction when opening a specially crafted Office file, leading to arbitrary code execution in the context of the current user.
What to do now
- Check which Microsoft Office products and versions are installed on all business PCs (especially Microsoft Office 365 for Mac and Office LTSC for Mac 2021/2024), and whether Office can open files from email, chat, or the internet.
- Install the available Microsoft Office security updates from Microsoft’s Office Security Releases guidance for CVE-2026-63519.
- For Microsoft Office 365 for Mac and Microsoft Office LTSC for Mac (2021 and 2024), upgrade to version 16.112.26081010 or later.
- If you can’t patch immediately, limit who can open unknown attachments and block suspicious Office files at the email/gateway level until updates are applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-63519 and every CVE in our database. Create a free account — no credit card required.
Create Free Account