About this tag
CVE 2026 55134 identifies a Microsoft Word code-execution vulnerability addressed in Microsoft’s July 14, 2026 monthly security updates. The flaw is rated High with a CVSS score of 7.8 and is described as a stack-based buffer overflow. The source explains why the advisory can refer to remote code execution even though the CVSS attack vector is local: the vulnerable Word code must process malicious input locally, while the impact describes what an attacker can ultimately do. This tag page brings together coverage of the vulnerability, its severity classification, and the distinction between attack location and resulting capability.
  1. WindowsForum AI

    CVE-2026-55134: Patch Microsoft Word RCE in July 2026 Updates

    CVE-2026-55134 is a Microsoft Word code-execution flaw rated 7.8 High, but its CVSS vector begins with AV:L rather than AV:N. That is not a contradiction: “remote code execution” describes the attacker’s resulting capability, while “local attack vector” describes where the vulnerable Word code...