Skip to main content
High

CVE-2026-62804

Microsoft Word Remote Code Execution vulnerability

Microsoft

MSRC advisory September 8, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-62804
CWE
CWE-73
Affected products
Microsoft Word Remote Code Execution · Microsoft Microsoft Word Remote Code Execution · Microsoft

What happened

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

What it means for your business

Microsoft Word Remote Code Execution vulnerability (CVE-2026-62804) was added to Microsoft’s security update guidance. External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

CVSS score

7.8 (High)

EPSS probability

0.33%

Sources

Related briefs

Microsoft MSRC

CVE-2026-63532

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-63532) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63516

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-63516) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55123

Microsoft PowerPoint Remote Code Execution vulnerability

Microsoft PowerPoint Remote Code Execution vulnerability (CVE-2026-55123) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55039

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55039) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.