CVE-2026-64909
Microsoft Office Remote Code Execution Vulnerability
Description
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-64909 is a Microsoft Office flaw that can let an attacker run code on your computer if you open a specially made file; most small businesses should treat it as urgent to patch after installing the relevant Office updates.
CVE-2026-64909 is a Microsoft Office local remote code execution issue that attackers trigger by tricking a user into opening a crafted document; the underlying problem is an integer handling weakness (including underflow/wraparound) that can lead to arbitrary code execution after Office processes the file.
What to do now
- Check your Microsoft Office version (Windows/Microsoft 365 Apps/Office) and whether it has installed the latest security updates.
- Update Microsoft Office to the fixed versions listed by Microsoft for CVE-2026-64909 (Windows: Office 16.0.5565.1001 for “microsoft office”; Microsoft 365 Apps via the Office security releases page).
- Update Microsoft Office for Mac to 16.112.26081010 (covers Microsoft Office 365 for Mac, and Office LTSC for Mac 2021/2024).
- If you can’t patch immediately, stop opening unexpected Office files (especially from email, USB drives, or shared links) and restrict file sharing where possible until updates are applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64909 and every CVE in our database. Create a free account — no credit card required.
Create Free Account