CVE-2026-45463 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. EPSS estimates a 0.34% chance of exploitation in the next 30 days.

## Description

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

## Metrics

CVSS 3.1 8.4/10  
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H  
EPSS Probability 0.34%  
26.3th percentile  
Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-121](https://cwe.mitre.org/data/definitions/121.html)
- [CWE-191](https://cwe.mitre.org/data/definitions/191.html)

## Affected Software

| Vendor    | Product          | Versions      |
|-----------|------------------|---------------|
| Microsoft | 365 Apps         | All versions  |
| Microsoft | 365 Copilot      | All versions  |
| Microsoft | Microsoft 365    | All versions  |
| Microsoft | Office 2016      | All versions  |
| Microsoft | Office 2019      | All versions  |
| Microsoft | Office 2021      | All versions  |
| Microsoft | Office 2024      | All versions  |

## References

- [Vendor Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463)

## Timeline

Published Jun 9, 2026  
Last Modified Jul 23, 2026  
Status Modified

## Frequently Asked Questions

**What is CVE-2026-45463?**  
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

**How severe is CVE-2026-45463?**  
CVE-2026-45463 has a CVSS score of 8.4/10 (HIGH severity). The EPSS model estimates a 0.34% probability of exploitation in the next 30 days.

**How do I fix CVE-2026-45463?**  
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.

## Related CVEs from 2026

- [CVE-2026-45458 Use after free in Microsoft Office allows an unauthorized attacker.](/content/cve/CVE-2026-45458/index.html)
- [CVE-2026-45459 Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker.](/content/cve/CVE-2026-45459/index.html)
- [CVE-2026-4546 A weakness has been identified in Flos Freeware Notepad2 4.2.](/content/cve/CVE-2026-4546/index.html)
- [CVE-2026-45460 Buffer over-read in Microsoft Office allows an unauthorized attacker.](/content/cve/CVE-2026-45460/index.html)
- [CVE-2026-45461 Use after free in Microsoft Office allows an unauthorized attacker.](/content/cve/CVE-2026-45461/index.html)
- [CVE-2026-45462 Improper neutralization of input during web page generation allows an unauthorized attacker.](/content/cve/CVE-2026-45462/index.html)
- [CVE-2026-45464 Improper neutralization of input during web page generation allows an unauthorized attacker.](/content/cve/CVE-2026-45464/index.html)
- [CVE-2026-45465 Improper neutralization of input during web page generation allows an unauthorized attacker.](/content/cve/CVE-2026-45465/index.html)
- [CVE-2026-45466 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker.](/content/cve/CVE-2026-45466/index.html)
- [CVE-2026-45467 Improper neutralization of input during web page generation allows an unauthorized attacker.](/content/cve/CVE-2026-45467/index.html)
- [CVE-2026-45468 Improper neutralization of input during web page generation allows an unauthorized attacker.](/content/cve/CVE-2026-45468/index.html)
- [CVE-2026-45469 Integer underflow (wrap or wraparound) in Microsoft Office E allows an unauthorized attacker.](/content/cve/CVE-2026-45469/index.html)

Source: [NVD / NIST](https://nvd.nist.gov/vuln/detail/CVE-2026-45463)
