The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check every Office installation you use (Microsoft 365 Apps / Microsoft Office / Office 2019, 2021, 2024, plus any macOS versions of “Microsoft Office 365 for Mac” or “Microsoft Office LTSC for Mac 2021/2024”) and record the current version/build.
For Microsoft Office 365 for Mac and both Microsoft Office LTSC for Mac 2021 and 2024, confirm you are on version 16.112.26081010 or later (fixed version).
For Microsoft 365 Apps and Microsoft Office on Windows, update Office using Microsoft’s Office security release guidance for CVE-2026-64910 (see the Microsoft Office security releases link) and confirm the update completed.
After updating, verify that the Office apps launch normally and that your next scheduled updates are enabled so you don’t fall behind again.
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
In plain language
Written by AI from the record
CVE-2026-64910 is a Microsoft Office flaw that could let an attacker run code on your computer if you open a specially crafted Office file; you should update soon because this type of Office “open document” bug is one of the more common routes for real-world attacks.
CVE-2026-64910 is a Microsoft Office remote code execution vulnerability (CWE-822) that can be triggered when Office processes an untrusted, specially crafted document; Microsoft has released fixed builds for multiple Office products, including macOS versions 16.112.26081010.
If you're affected
Full device compromise
Ransomware staging
Data theft from Office files
Operational disruption
What is it
This flaw is a “crash-to-code” type of Office bug: when Office reads a malicious document, it can accidentally follow a bad in-memory reference. If the conditions line up, that mistake can be turned into instructions that run on your computer.
Think of it like a document-reader that sometimes misinterprets a sentence and ends up jumping to the wrong part of the book—an attacker may try to use that jump to get the computer to do something they choose.
Who is affected
This matters if your business runs any of these: Microsoft 365 Apps, Microsoft Office, Microsoft 365, Office 2019, Office 2021, Office 2024, or the listed Microsoft Office macOS variants.
Because Microsoft Office file handling is involved, the practical risk is highest when employees receive and open Office documents from untrusted sources. The reachability gate here includes needing access to a vulnerable Office environment and then getting the crafted document to be opened (no confirmed “always on” remote attack is indicated by the findings).
How urgent is it
This is a RED issue because it’s a Microsoft Office remote code execution vulnerability affecting common business document software. Even without a confirmed KEV listing or a public exploit on record, Office “open a document” bugs are a common pathway to compromise.
Microsoft has already provided fixed versions, including specific macOS builds, so you can reduce exposure quickly by updating now rather than waiting.
What to do — in detail
Confirm whether you’re exposed
Identify where the affected Office apps are installed:
Windows: Microsoft 365 Apps and Microsoft Office (also applies to Office 2019/2021/2024 per the affected list).
macOS: Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024.
For each device, check the installed Office build/version:
macOS: in any Office app, use the app’s “About” / version screen to read the build number.
Windows: use Office’s version/about page (or your admin tooling) to capture the build.
Apply the fixed versions
macOS (explicit fixed build from Microsoft):
Update Microsoft Office 365 for Mac to 16.112.26081010 or later.
Update Microsoft Office LTSC for Mac 2021 to 16.112.26081010 or later.
Update Microsoft Office LTSC for Mac 2024 to 16.112.26081010 or later.
Windows / other impacted Microsoft Office products:
Follow Microsoft’s Office security release guidance for CVE-2026-64910 (Microsoft’s Office security releases link and the CVE-2026-64910 update guide).
Ensure the update actually completes and that the Office “About” version/build reflects the patched level.
If you can’t patch immediately
Reduce the chance of exposure in the meantime by treating incoming Office attachments from outside your organization as untrusted until patched.
Prioritize updating the machines that most often receive external documents (email gateway exceptions, shared inboxes, or receptionist/admin accounts).
What to monitor after patching
Confirm Office updates continue to apply as scheduled (so systems don’t drift back).
Watch for any suspicious endpoint activity on devices that were not updated yet (especially around the time an external document was opened), and then complete patching without delay.
KEV/CISA note
CVE-2026-64910 is not listed in the CISA KEV findings provided with this request, and there is no public exploit code on record in the provided findings.
Technical context
Summary
CVE: CVE-2026-64910
Affected products (as provided): microsoft 365 apps, microsoft office, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, microsoft 365, office 2019, office 2021, office 2024.
The findings describe Microsoft Office as allowing code execution when processing an untrusted input that leads to an untrusted pointer dereference.
The provided CVSS vector indicates user interaction is required (UI:R) and the attack path is not purely network-reachable without involving a user opening/handling something.
Exploitation status
The provided findings state: no public exploit code on record.
The provided findings also state: CVE-2026-64910 is not listed in the CISA KEV dataset.
Press attention is noted (patch-related) and an actor name is mentioned (“Lazarus group”) in the findings; however, the findings do not provide proof of exploitation.
Fix information
macOS fixed in: 16.112.26081010 for Microsoft Office 365 for Mac and both Office LTSC for Mac 2021/2024.
Windows/other Microsoft Office products are addressed via Microsoft’s Office security releases and the update guide for CVE-2026-64910 (links provided in the findings).
EPSS
EPSS is provided as a prediction in the findings (flat trend). Per the instructions, the prediction value is not reproduced in the public-facing owner blocks.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.