๐Ÿ” CVE Alert

CVE-2026-81955

HIGH 8.8

Windows Graphics Component Remote Code Execution Vulnerability

CVSS Score
8.8
EPSS Score
0.6%
EPSS Percentile
47th

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Vendor microsoft
Product microsoft 365 apps for enterprise
Ecosystems
Industries
TechnologyEnterprise
Published Sep 8, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft microsoft 365 apps for enterprise

Be the first to know when new high vulnerabilities affecting microsoft microsoft 365 apps for enterprise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Microsoft / Microsoft 365 Apps for Enterprise
16.0.1 < 16.0.20326.20138
Microsoft / Microsoft Office 2016
16.0.0 < 16.0.5569.1003
Microsoft / Microsoft Office 2019
19.0.0 < 16.0.10417.20207
Microsoft / Microsoft Office 365 for Mac
-
Microsoft / Microsoft Office LTSC 2021
16.0.1 < 16.0.14334.20906
Microsoft / Microsoft Office LTSC 2024
16.0.0 < 16.0.17932.20976
Microsoft / Microsoft Office LTSC for Mac 2021
-
Microsoft / Microsoft Office LTSC for Mac 2024
-
Microsoft / Windows 10 Version 1607
10.0.14393.0 < 10.0.14393.9504
Microsoft / Windows 10 Version 1809
10.0.17763.0 < 10.0.17763.9245
Microsoft / Windows 10 Version 21H2
10.0.19044.0 < 10.0.19044.7725
Microsoft / Windows 10 Version 22H2
10.0.19045.0 < 10.0.19045.7725
Microsoft / Windows 11 version 23H2
10.0.22631.0 < 10.0.22631.7582
Microsoft / Windows 11 Version 23H2
10.0.22631.0 < 10.0.22631.7582
Microsoft / Windows 11 Version 24H2
10.0.26100.0 < 10.0.26100.9445
Microsoft / Windows 11 Version 25H2
10.0.26200.0 < 10.0.26200.9445
Microsoft / Windows 11 version 26H1
10.0.28000.0 < 10.0.28000.2954
Microsoft / Windows Server 2012
6.2.9200.0 < 6.2.9200.26349
Microsoft / Windows Server 2012 (Server Core installation)
6.2.9200.0 < 6.2.9200.26349
Microsoft / Windows Server 2012 R2
6.3.9600.0 < 6.3.9600.23397
Microsoft / Windows Server 2012 R2 (Server Core installation)
6.3.9600.0 < 6.3.9600.23397
Microsoft / Windows Server 2016
10.0.14393.0 < 10.0.14393.9504
Microsoft / Windows Server 2016 (Server Core installation)
10.0.14393.0 < 10.0.14393.9504
Microsoft / Windows Server 2019
10.0.17763.0 < 10.0.17763.9245
Microsoft / Windows Server 2019 (Server Core installation)
10.0.17763.0 < 10.0.17763.9245
Microsoft / Windows Server 2022
10.0.20348.0 < 10.0.20348.5622
Microsoft / Windows Server 2025
10.0.26100.0 < 10.0.26100.33438
Microsoft / Windows Server 2025 (Server Core installation)
10.0.26100.0 < 10.0.26100.33438

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
msrc.microsoft.com: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81955