Microsoft Office Word: 17 Vulnerabilities Including RCE Flaws Disclosed Together
Microsoft Office Word users face risks from 17 vulnerabilities disclosed on August 11, 2026, including flaws allowing local code execution and information disclosure.

Key findings
- 17 vulnerabilities in Microsoft Office Word disclosed on August 11, 2026.
- Multiple high-severity flaws allow for local code execution via buffer overflows and related memory corruption.
- Several medium-severity vulnerabilities enable local information disclosure through improper input validation and out-of-bounds reads.
- Exploitation in the wild was noted for other vulnerabilities in the August 2026 Patch Tuesday, highlighting the need for prompt patching.
- Users should update Microsoft Office Word to the latest version to address these security risks.
On August 11, 2026, Microsoft released a significant security update addressing 17 vulnerabilities in Microsoft Office Word. This batch of disclosures, all published within minutes of each other, includes a mix of critical and medium severity flaws, with several allowing for local code execution. The vulnerabilities primarily stem from common memory corruption issues such as buffer overflows, use-after-free, and out-of-bounds reads, which attackers can exploit by tricking users into opening specially crafted Word documents.
A notable group of high-severity vulnerabilities (CVSSv3 7.8) are related to buffer overflows and buffer over-reads. These include CVE-2026-70311, CVE-2026-64915, CVE-2026-64907, CVE-2026-64905, CVE-2026-63527, CVE-2026-63518, and CVE-2026-58651. Successful exploitation of these flaws could allow an attacker to execute code locally on a victim's machine. Additionally, CVE-2026-63525, a numeric truncation error, also carries a high severity and the potential for local code execution.
Several other vulnerabilities, classified as medium severity (CVSSv3 5.5), focus on information disclosure. These include improper input validation in CVE-2026-70319, out-of-bounds reads in CVE-2026-70310, CVE-2026-64917, CVE-2026-63531, CVE-2026-63530, and CVE-2026-63528, and a heap-based buffer overflow in CVE-2026-66810. An off-by-one error in CVE-2026-66806 also falls into this category. These vulnerabilities could allow an attacker to gain local access to sensitive information.
While the provided information does not explicitly state which specific Office Word vulnerabilities were exploited in the wild, general reporting from the August 2026 Patch Tuesday indicates that Microsoft was aware of exploitation for at least one vulnerability disclosed that month, though it was not specifically tied to Office Word in the provided excerpts. However, the sheer volume and severity of the Office Word vulnerabilities suggest a high priority for patching.
Microsoft's August 2026 Patch Tuesday addressed these vulnerabilities. Users are advised to update their Microsoft Office suite to the latest available version to mitigate the risks associated with these flaws. Specific version numbers for the patches were not detailed in the provided information, but the disclosure of these vulnerabilities alongside other security updates implies that they are addressed in the August 2026 cumulative updates.
This batch of vulnerabilities underscores the ongoing security challenges within complex software like Microsoft Office. Users of Microsoft Office Word should prioritize applying security updates promptly to protect against potential local code execution and information disclosure attacks. Continued vigilance and timely patching remain critical for maintaining a secure computing environment.