CVE-2026-66807
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Description
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowThis Microsoft Office graphics feature has a memory bug that can let an attacker run code when a specially crafted Office file is opened; most small businesses should update Office right away, especially if staff open emailed attachments or files from outside the company.
CVE-2026-66807 is a stack-based buffer overflow in the Microsoft Office Graphics component that can be triggered when a user opens a malicious Office document, potentially enabling local remote code execution (with user interaction) in Microsoft Office/ Microsoft 365 apps and the listed Mac Office editions.
What to do now
- Check which Microsoft Office product and exact version your company uses (including Windows Microsoft 365/Office and any Mac Microsoft Office versions).
- Verify whether you are already on the fixed versions listed by Microsoft—on Mac, confirm you are at 16.112.26081010.
- Update Microsoft Office using Microsoft’s Office security update guidance (see the Microsoft Office Security Releases / the CVE’s update guide) so you move to the fixed builds.
- Until you finish updating, reduce risk by blocking or quarantining unexpected Office attachments from email and only opening files from trusted sources.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-66807 and every CVE in our database. Create a free account — no credit card required.
Create Free Account