AI analysis
CVE-2026-73006 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component that an unauthenticated attacker can exploit remotely to execute code. The CVSS vector (AV:N/PR:N/UI:R) indicates the attack requires user interaction, meaning it is most likely triggered when a user opens or previews attacker-supplied content, such as a crafted document or image, that the Graphics Component renders. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, typically in the context of the application or user handling the content. Affected systems are those running the impacted Microsoft software that includes the Graphics Component; specific product lists and version ranges are not enumerated in the available data, though related coverage ties the fix to Microsoft's September 2026 security updates. Exploitation is not currently observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a 0.8% probability of exploitation within 30 days (55th percentile).
What to do: Apply Microsoft's September 2026 security updates to all Windows systems as soon as feasible, prioritizing hosts that process untrusted files such as workstations, mail clients, and file-handling servers. No workaround is documented in the available data; because user interaction is required, caution around opening or previewing untrusted documents and images adds defense in depth. Verify patch compliance through Windows Update/WSUS and your vulnerability management tooling.
Affected
| Microsoft Graphics Component | — |
Estimated exposure
masseffectively every supported Windows installation — on the order of 1 billion+ devices — The Graphics Component ships as a core rendering library on essentially all Windows machines, and Microsoft's Windows install base is publicly estimated at over a billion devices, though the portion of hosts with the specific vulnerable…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.