CVE-2026-81955

Summary

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1 < 16.0.20326.20138affected
MicrosoftMicrosoft Office 201616.0.0 < 16.0.5569.1003affected
MicrosoftMicrosoft Office 201919.0.0 < 16.0.10417.20207affected
MicrosoftMicrosoft Office 365 for Mac-affected
MicrosoftMicrosoft Office LTSC 202116.0.1 < 16.0.14334.20906affected
MicrosoftMicrosoft Office LTSC 202416.0.0 < 16.0.17932.20976affected
MicrosoftMicrosoft Office LTSC for Mac 2021-affected
MicrosoftMicrosoft Office LTSC for Mac 2024-affected
MicrosoftWindows 10 Version 160710.0.14393.0 < 10.0.14393.9504affected
MicrosoftWindows 10 Version 180910.0.17763.0 < 10.0.17763.9245affected
MicrosoftWindows 10 Version 21H210.0.19044.0 < 10.0.19044.7725affected
MicrosoftWindows 10 Version 22H210.0.19045.0 < 10.0.19045.7725affected
MicrosoftWindows 11 version 23H210.0.22631.0 < 10.0.22631.7582affected
MicrosoftWindows 11 Version 23H210.0.22631.0 < 10.0.22631.7582affected
MicrosoftWindows 11 Version 24H210.0.26100.0 < 10.0.26100.9445affected
MicrosoftWindows 11 Version 25H210.0.26200.0 < 10.0.26200.9445affected
MicrosoftWindows 11 version 26H110.0.28000.0 < 10.0.28000.2954affected
MicrosoftWindows Server 20126.2.9200.0 < 6.2.9200.26349affected
MicrosoftWindows Server 2012 (Server Core installation)6.2.9200.0 < 6.2.9200.26349affected
MicrosoftWindows Server 2012 R26.3.9600.0 < 6.3.9600.23397affected
MicrosoftWindows Server 2012 R2 (Server Core installation)6.3.9600.0 < 6.3.9600.23397affected
MicrosoftWindows Server 201610.0.14393.0 < 10.0.14393.9504affected
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0 < 10.0.14393.9504affected
MicrosoftWindows Server 201910.0.17763.0 < 10.0.17763.9245affected
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0 < 10.0.17763.9245affected
MicrosoftWindows Server 202210.0.20348.0 < 10.0.20348.5622affected
MicrosoftWindows Server 202510.0.26100.0 < 10.0.26100.33438affected
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0 < 10.0.26100.33438affected

Weaknesses

  • CWE-122: CWE-122: Heap-based Buffer Overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References