CVE-2026-64904: Microsoft Office Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64904?
CVE-2026-64904 has a severity rating of high with a score of 7.8.
How do I fix CVE-2026-64904?
To mitigate CVE-2026-64904, apply the latest security updates provided by Microsoft for the affected Office versions.
What impact does CVE-2026-64904 have?
CVE-2026-64904 allows an unauthorized attacker to execute code locally on the affected Microsoft Office applications.
Which Microsoft Office versions are affected by CVE-2026-64904?
CVE-2026-64904 affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, and Microsoft Office LTSC 2021.
When was CVE-2026-64904 published?
CVE-2026-64904 was published on August 11, 2026.