CVE-2026-63526: Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published Aug 11, 2026
·Updated
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Other sources
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
1 affected component
Microsoft Microsoft Office
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63526?
CVE-2026-63526 has a high severity rating of 7.8.
2
How do I fix CVE-2026-63526?
To fix CVE-2026-63526, ensure that your Microsoft Office software is updated with the latest security patches.
3
What type of vulnerability is CVE-2026-63526?
CVE-2026-63526 is a stack-based buffer overflow vulnerability.
4
What can an attacker achieve with CVE-2026-63526?
An attacker can execute arbitrary code locally on a vulnerable Microsoft Office installation.
5
Is CVE-2026-63526 due to insufficient user authentication?
No, CVE-2026-63526 does not require user authentication for exploitation.