CVE-2026-81955: Microsoft 365 Apps For Enterprise
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Affected products
- Microsoft Microsoft 365 Apps For Enterprise: from 16.0.1, before 16.0.20326.20138 (fixed in 16.0.20326.20138)
- Microsoft Microsoft Office 2016: from 16.0.0, before 16.0.5569.1003 (fixed in 16.0.5569.1003)
- Microsoft Microsoft Office 2019: from 19.0.0, before 16.0.10417.20207 (fixed in 16.0.10417.20207)
- Microsoft Microsoft Office 365 For Mac: from 1.0.0, before 16.113.26091433 (fixed in 16.113.26091433)
- Microsoft Microsoft Office Ltsc 2021: from 16.0.1, before 16.0.14334.20906 (fixed in 16.0.14334.20906)
- Microsoft Microsoft Office Ltsc 2024: from 16.0.0, before 16.0.17932.20976 (fixed in 16.0.17932.20976)
- Microsoft Microsoft Office Ltsc For Mac 2021: from 16.0.1, before 16.113.26091433 (fixed in 16.113.26091433)
- Microsoft Microsoft Office Ltsc For Mac 2024: from 16.0.0, before 16.113.26091433 (fixed in 16.113.26091433)
- Microsoft Windows 10 Version 1607: from 10.0.14393.0, before 10.0.14393.9504 (fixed in 10.0.14393.9504)
- Microsoft Windows 10 Version 1809: from 10.0.17763.0, before 10.0.17763.9245 (fixed in 10.0.17763.9245)
- Microsoft Windows 10 Version 21h2: from 10.0.19044.0, before 10.0.19044.7725 (fixed in 10.0.19044.7725)
- Microsoft Windows 10 Version 22h2: from 10.0.19045.0, before 10.0.19045.7725 (fixed in 10.0.19045.7725)
- Microsoft Windows 11 Version 23h2: from 10.0.22631.0, before 10.0.22631.7582 (fixed in 10.0.22631.7582)
- Microsoft Windows 11 Version 24h2: from 10.0.26100.0, before 10.0.26100.9445 (fixed in 10.0.26100.9445)
- Microsoft Windows 11 Version 25h2: from 10.0.26200.0, before 10.0.26200.9445 (fixed in 10.0.26200.9445)
- Microsoft Windows 11 Version 26h1: from 10.0.28000.0, before 10.0.28000.2954 (fixed in 10.0.28000.2954)
- Microsoft Windows Server 2012: from 6.2.9200.0, before 6.2.9200.26349 (fixed in 6.2.9200.26349)
- Microsoft Windows Server 2012 r2: from 6.3.9600.0, before 6.3.9600.23398 (fixed in 6.3.9600.23398)
- Microsoft Windows Server 2012 r2 Server Core Installation: from 6.3.9600.0, before 6.3.9600.23398 (fixed in 6.3.9600.23398)
- Microsoft Windows Server 2012 Server Core Installation: from 6.2.9200.0, before 6.2.9200.26349 (fixed in 6.2.9200.26349)
- Microsoft Windows Server 2016: from 10.0.14393.0, before 10.0.14393.9504 (fixed in 10.0.14393.9504)
- Microsoft Windows Server 2016 Server Core Installation: from 10.0.14393.0, before 10.0.14393.9504 (fixed in 10.0.14393.9504)
- Microsoft Windows Server 2019: from 10.0.17763.0, before 10.0.17763.9245 (fixed in 10.0.17763.9245)
- Microsoft Windows Server 2019 Server Core Installation: from 10.0.17763.0, before 10.0.17763.9245 (fixed in 10.0.17763.9245)
- Microsoft Windows Server 2022: from 10.0.20348.0, before 10.0.20348.5622 (fixed in 10.0.20348.5622)
- and 2 more
Published 2026-09-08. Last modified 2026-09-24.