CVE-2026-64910
Microsoft Office Remote Code Execution Vulnerability
Description
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-64910 is a Microsoft Office flaw that could let an attacker run code on your computer if you open a specially crafted Office file; you should update soon because this type of Office “open document” bug is one of the more common routes for real-world attacks.
CVE-2026-64910 is a Microsoft Office remote code execution vulnerability (CWE-822) that can be triggered when Office processes an untrusted, specially crafted document; Microsoft has released fixed builds for multiple Office products, including macOS versions 16.112.26081010.
What to do now
- Check every Office installation you use (Microsoft 365 Apps / Microsoft Office / Office 2019, 2021, 2024, plus any macOS versions of “Microsoft Office 365 for Mac” or “Microsoft Office LTSC for Mac 2021/2024”) and record the current version/build.
- For Microsoft Office 365 for Mac and both Microsoft Office LTSC for Mac 2021 and 2024, confirm you are on version 16.112.26081010 or later (fixed version).
- For Microsoft 365 Apps and Microsoft Office on Windows, update Office using Microsoft’s Office security release guidance for CVE-2026-64910 (see the Microsoft Office security releases link) and confirm the update completed.
- After updating, verify that the Office apps launch normally and that your next scheduled updates are enabled so you don’t fall behind again.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64910 and every CVE in our database. Create a free account — no credit card required.
Create Free Account