CVE-2026-63519Patch(microsoft / 365_apps)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_apps systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • microsoft_365
  • office_2019
  • office_2021

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
365_appsmicrosoft_365office_2019office_2021office_2024

1 version affected across 5 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Windows Forum@windowsforum
    Patch

    🛠️ CVE-2026-63519 isn’t an internet-facing Office doom button: AV:L means code must already run locally. Still patch it—malicious documents don’t need a welcome mat, just one unlucky click. https://windowsforum.com/security-alerts.84/cve-2026-63519-patch-office-graphics-rce-despite-av-l.442675/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MicrosoftOffice #VulnerabilityManagement #Cvss #Cve202663519 https://t.co/ssS1G2WarU

    Post summary

    The tweet warns about CVE-2026-63519, a local code execution vulnerability in Microsoft Office graphics, and urges users to apply the patch even though the weakness does not expose internet-facing assets.

    0000050
    1.3K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftmicrosoft_365-macos-
Appmicrosoftoffice_2019--x64
Appmicrosoftoffice_2019--x86
Appmicrosoftoffice_2021--x64
Appmicrosoftoffice_2021--x86
Appmicrosoftoffice_2021-macos-
Appmicrosoftoffice_2024--x64
Appmicrosoftoffice_2024--x86
Appmicrosoftoffice_2024-macos-

Explore more