Heap-based buffer overflow in Microsoft Office for macOS and Microsoft Outlook - CVE-2026-63518
Published: August 12, 2026
Vulnerability identifier: #VU141800
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63518
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.
User interaction is required to open the crafted file.
Affected software
Microsoft Office for macOS
Microsoft Outlook
Microsoft Outlook
How to mitigate CVE-2026-63518
Install security update from vendor's website.
Microsoft Office for macOS - update to 16.112.26081010
Microsoft Outlook - update to 16.0.5565.1000
Microsoft Outlook - update to 16.0.5565.1000