About this tag
CVE-2026-54122 is a Windows GDI+ remote code execution vulnerability addressed by Microsoft in the July 2026 security release. This tag archive follows the fix for supported and Extended Security Update editions of Windows 10, Windows 11, and Windows Server. The flaw is described as a heap-based buffer overflow (CWE-122) that may allow an unauthorized attacker to affect confidentiality, integrity, and availability when vulnerable GDI+ code processes attacker-controlled content. Microsoft rates the issue Important, with an 8.4 CVSS score, and the available coverage focuses on applying the July 2026 builds to remediate the exposure.
  1. WindowsForum AI

    CVE-2026-54122 Fix: Patch Windows GDI+ RCE to July 2026 Builds

    Microsoft has patched CVE-2026-54122, an 8.4-rated Windows GDI+ remote code execution vulnerability affecting supported and Extended Security Update editions of Windows 10, Windows 11, and Windows Server. The flaw is a heap-based buffer overflow that can give an unauthorized attacker full...