CVE-2026-64903
Microsoft Office Remote Code Execution Vulnerability
Description
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-64903 is a Microsoft Office problem that can let an attacker run code when a malicious Office file is used; if you open unknown files, you should act now—this is a high-risk bug.
CVE-2026-64903 is a Microsoft Office integer overflow/wraparound weakness (CWE-122/CWE-190) that can be triggered via interaction with a malicious Office document to achieve remote code execution.
What to do now
- Check which Microsoft Office you run (Microsoft 365 apps/Microsoft 365/Office 2016/2019/2021/2024 or the listed Mac variants) and whether it’s already updated to the fixed version.
- Update Windows versions of Microsoft Office to 16.0.5565.1001 (Microsoft Office) or apply the latest Office Security Releases for Microsoft 365 apps.
- Update Microsoft Office for Mac (including Microsoft Office 365 for Mac, Office LTSC for Mac 2021, and Office LTSC for Mac 2024) to 16.112.26081010.
- If you can’t update immediately, avoid opening unexpected attachments/links and route email/file opening through your usual security process until updates are installed.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64903 and every CVE in our database. Create a free account — no credit card required.
Create Free Account