ZeroHour

CVE-2026-72986

mass

Heap Buffer Overflow RCE in Microsoft Windows Graphic Fonts

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-72986 is a heap-based buffer overflow (with an underlying integer overflow, per CWE-190) in the Graphic Fonts component assigned by Microsoft, the part of the Windows font-parsing/rendering stack that processes font data. An unauthorized, unauthenticated remote attacker can trigger the flaw by getting a user to load maliciously crafted font content — the CVSS vector requires user interaction, consistent with the victim opening a crafted document, email attachment, or web content that renders the malicious font. Successful exploitation gives the attacker arbitrary code execution on the victim system, with high impact to confidentiality, integrity, and availability. Anyone running affected Microsoft software that renders untrusted fonts is exposed until patched, which given the component is effectively the broad Windows installed base. As of this data there is no known public proof-of-concept, it is not in CISA's KEV catalog, EPSS estimates only a ~0.8% chance of exploitation within 30 days, and the fix shipped in Microsoft's September 2026 security updates.

What to do: Apply Microsoft's September 2026 security updates to all Windows systems as soon as your patch cycle allows, prioritizing endpoints and servers that routinely handle untrusted documents, email attachments, or web content, and confirm the affected version ranges for your specific Windows builds in Microsoft's Security Update Guide. Until patched, caution users about opening untrusted font-bearing files, since exploitation requires user interaction; no public PoC or in-the-wild exploitation is currently known.

Affected
Microsoft Graphic Fonts component (font rendering in Microsoft Windows; exact affected Windows releases per Microsoft's advisory)
Estimated exposure
mass≈1–1.5 billion Windows devices (essentially the entire unpatched Windows installed base, since the font-parsing component ships with the OS) — Graphic Fonts is part of the standard Microsoft/Windows font-rendering stack, so exposure scales with the Windows installed base (public trackers put Windows at roughly 70% desktop share, ~1.5B+ devices), though practically exploitable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.