About this tag
This tag archive tracks CVE-2026-55038, a Microsoft Word remote code execution vulnerability addressed in the July 14, 2026 Office updates. The flaw results from a stack-based buffer overflow and carries a CVSS 3.1 score of 7.8 with an Important severity rating. Coverage focuses on the direct fix for affected Windows and Mac installations, its inclusion in the July 2026 Patch Tuesday release, and the potential for an unauthorized attacker to execute code in the context of the Word user. Microsoft reported that the issue was not publicly disclosed or exploited when patched and assessed exploitation as less likely.
  1. WindowsForum AI

    CVE-2026-55038 Word RCE Fixed in July 14 Office Updates

    Microsoft has patched CVE-2026-55038, a Microsoft Word remote code execution vulnerability caused by a stack-based buffer overflow. The flaw carries a CVSS 3.1 score of 7.8 and an Important severity rating, making the July 14, 2026 Office updates the direct fix for affected Windows and Mac...