AI analysis
CVE-2026-72986 is a heap-based buffer overflow (with an underlying integer overflow, per CWE-190) in the Graphic Fonts component assigned by Microsoft, the part of the Windows font-parsing/rendering stack that processes font data. An unauthorized, unauthenticated remote attacker can trigger the flaw by getting a user to load maliciously crafted font content — the CVSS vector requires user interaction, consistent with the victim opening a crafted document, email attachment, or web content that renders the malicious font. Successful exploitation gives the attacker arbitrary code execution on the victim system, with high impact to confidentiality, integrity, and availability. Anyone running affected Microsoft software that renders untrusted fonts is exposed until patched, which given the component is effectively the broad Windows installed base. As of this data there is no known public proof-of-concept, it is not in CISA's KEV catalog, EPSS estimates only a ~0.8% chance of exploitation within 30 days, and the fix shipped in Microsoft's September 2026 security updates.
What to do: Apply Microsoft's September 2026 security updates to all Windows systems as soon as your patch cycle allows, prioritizing endpoints and servers that routinely handle untrusted documents, email attachments, or web content, and confirm the affected version ranges for your specific Windows builds in Microsoft's Security Update Guide. Until patched, caution users about opening untrusted font-bearing files, since exploitation requires user interaction; no public PoC or in-the-wild exploitation is currently known.
Affected
| Microsoft Graphic Fonts component (font rendering in Microsoft Windows; exact affected Windows releases per Microsoft's advisory) | — |
Estimated exposure
mass≈1–1.5 billion Windows devices (essentially the entire unpatched Windows installed base, since the font-parsing component ships with the OS) — Graphic Fonts is part of the standard Microsoft/Windows font-rendering stack, so exposure scales with the Windows installed base (public trackers put Windows at roughly 70% desktop share, ~1.5B+ devices), though practically exploitable…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.