17 July 2026
Reference: CVE-2026-50301
1. What is being reported?
There is a problem in Microsoft Office where a type of error called a 'heap-based buffer overflow' can allow someone to run harmful code on your computer. This means an attacker could take control of your device by exploiting this weakness.
2. What this means in plain English
If this flaw is exploited, an attacker could potentially access your files, install malware, or cause other damage without your knowledge. For small organisations, this could lead to data loss, disruption of work, or even financial harm.
3. Could this affect a small business?
Any small business or organisation using Microsoft Office on Windows could be affected, especially if they have not installed recent security updates. If you use other office software or do not use Microsoft Office, this is less likely to affect you.
4. What to do now
- Check that all your Microsoft Office software is fully updated with the latest security patches.
- If you have an IT provider, ask them to confirm that updates have been applied.
- Be cautious when opening unexpected or suspicious email attachments or files, even if they appear to come from known contacts.
- Ensure your antivirus software is up to date and running regular scans.
5. Ask your IT provider
Can you confirm that the latest security update addressing CVE-2026-50301 has been installed on all our Microsoft Office applications?
6. Bottom line
Apply Microsoft Office updates promptly to protect your organisation from this serious security risk.
Information based on CISA KEV, NVD, and reputable security reporting.