Microsoft’s July 2026 Patch Tuesday included
622 vulnerabilities
, but buried within that record-breaking number are nine critical remote code execution (RCE) flaws in Microsoft Office that demand immediate attention from UK SMEs. Unlike infrastructure vulnerabilities that require specialist knowledge to exploit, these Office flaws target the applications your staff use every single day—Word, Excel, PowerPoint, and Outlook.
What makes these vulnerabilities particularly dangerous is that
the Preview Pane is an attack vector for all nine vulnerabilities
affecting core Office applications. That means an attacker doesn’t need to convince a user to open a malicious file—simply previewing it in Outlook or File Explorer can trigger the exploit. For UK SMEs where email remains the primary business communication tool, this dramatically lowers the bar for successful attacks.
The 9 Critical Microsoft Office RCE Vulnerabilities Patched in July 2026
CVE-2026-55045, CVE-2026-50314, CVE-2026-50467, CVE-2026-55018, CVE-2026-55022, CVE-2026-55049, CVE-2026-55056, CVE-2026-55129, and CVE-2026-55140 are Critical RCE vulnerabilities in Microsoft Office
, allowing unauthenticated attackers to execute arbitrary code on your systems. The vulnerabilities stem from multiple memory corruption issues including heap-based buffer overflows, use-after-free flaws, type confusion, and out-of-bounds read errors.
Additionally,
three more Critical RCE vulnerabilities affect Microsoft PowerPoint (CVE-2026-55043, CVE-2026-55120, CVE-2026-55123) and three affect Microsoft Word (CVE-2026-55033, CVE-2026-55127, CVE-2026-55132)
, all rated with CVSS scores between 7.8 and 8.4. These bring the total number of critical Office RCE flaws to 15 across the product suite.
Why the Preview Pane Attack Vector Matters
Traditionally, Office-based attacks required social engineering to convince users to open malicious attachments. The Preview Pane vulnerability changes this calculus entirely. When a user selects an email in Outlook to preview it, or hovers over an Office file in Windows Explorer with preview enabled, the vulnerable code executes—no double-click required, no security warning displayed.
This has significant implications for UK SME security awareness training. Even employees who’ve been trained never to open suspicious attachments remain at risk if Preview Pane is enabled, which it is by default in most Office and Windows installations.
The CVE-2026-56195 Information Disclosure Flaw
Beyond the RCE vulnerabilities,
CVE-2026-56195, an out-of-bounds read flaw, could allow attackers to silently extract sensitive data from memory after a victim opens a malicious file
. This vulnerability affects every major Office version across Windows and Mac.
The vulnerability is an out-of-bounds read where the software reads data beyond the intended buffer, and if exploited, it could leak sensitive information like document fragments, credentials, or encryption keys that happen to be in memory
. While
no active attacks have been spotted yet
, the public disclosure of technical details means exploit code will likely emerge in the coming weeks.
The particular concern with information disclosure vulnerabilities is that they can be chained with other exploits. An attacker might use CVE-2026-56195 to extract credentials or encryption keys from memory, then use those to escalate privileges or move laterally across your network.
Context: AI-Accelerated Vulnerability Discovery
The volume of vulnerabilities Microsoft is now patching each month isn’t an accident.
Microsoft’s announcement that artificial intelligence is accelerating vulnerability discovery through its multi-model agentic scanning system, MDASH, integrates third-party research models to analyse Windows binaries and validate potential issues
.
This AI-driven discovery is a double-edged sword for UK SMEs. On one hand, Microsoft is finding and fixing vulnerabilities before attackers can exploit them. On the other, the sheer volume of patches—569 vulnerabilities in July’s Patch Tuesday alone—is creating a management burden that many small businesses struggle to handle without dedicated IT support.
As we covered in our recent article on AI-discovered vulnerabilities and record patch volumes, this trend shows no signs of slowing. UK SMEs need robust patch management processes, not just for this month’s Office updates, but for the sustained high-volume patching environment we’re now operating in.
What UK SMEs Must Do This Week
1. Update All Office Installations Immediately
The July 2026 security updates apply to Office 2016, Office 2019, Office LTSC 2021, Microsoft 365 Apps for Enterprise, and Office for Mac.
Office 2019 ended mainstream support on 14 October 2025, and the fact that a July 2026 security patch exists is a discretionary gesture, not a return to a supported lifecycle
. If you’re still running Office 2019, this is your wake-up call to plan a migration to a supported version.
For Microsoft 365 subscribers, updates should deploy automatically within 48 hours. For volume-licensed and standalone Office installations, you must either enable automatic updates through Windows Update or manually download and install the security updates from the Microsoft Update Catalog.
2. Disable Preview Pane in Outlook and File Explorer
Until all systems are fully patched, disable Preview Pane as a temporary mitigation. In Outlook, go to View → Reading Pane → Off. In File Explorer, go to View → Preview pane (untick). This removes the zero-click attack vector, requiring attackers to rely on social engineering instead.
This is a temporary measure—Preview Pane is a productivity feature that many users rely on. Once patching is complete and verified across your environment, you can re-enable it. However, the existence of Preview Pane exploits should inform your long-term security posture: defence-in-depth matters because any single feature can become an attack vector.
3. Verify Patch Deployment Across Remote and Hybrid Workers
The shift to hybrid working has created a patch management challenge for UK SMEs. Devices that aren’t regularly connected to corporate networks may miss critical updates. Microsoft’s security updates require either a connection to Windows Update, WSUS, or Microsoft Endpoint Configuration Manager (formerly SCCM).
If you manage IT in-house, use PowerShell or your RMM tool to audit Office versions across all endpoints. The vulnerable file versions and their patched replacements are documented in each CVE’s Microsoft Security Response Center entry. If you rely on users to self-patch, send a clear communication explaining the urgency and providing step-by-step instructions for manual updates.
4. Review Your Patch Management Process
These Office vulnerabilities are part of a broader pattern.
This month’s release addresses a whopping 570 vulnerabilities, including 57 critical and 510 important-severity vulnerabilities
across Microsoft’s product ecosystem. For context, that’s more vulnerabilities in a single month than Microsoft typically patched in an entire quarter just three years ago.
If your current patch management process involves “we’ll get round to it when we can,” it’s time for a fundamental rethink. Modern patch management for UK SMEs needs to include:
- Automated patch deployment for workstations and servers, ideally within 72 hours of release for critical vulnerabilities
- Centralised visibility into patch status across all endpoints, including remote workers
- Risk-based prioritisation—not every patch is equally urgent, but RCE vulnerabilities affecting daily-use applications like Office must be treated as emergencies
- A rollback plan in case patches cause application compatibility issues
- Regular audits to identify systems that consistently miss patches
The volume of patches Microsoft now releases monthly has made ad-hoc patching untenable. You need either in-house expertise with proper tooling (WSUS, Intune, or a third-party RMM platform) or a relationship with a managed IT provider who handles this as part of their service. As we explored in our guide to handling Microsoft’s record patch volumes, the “set it and forget it” approach to Windows Update is no longer sufficient.
5. Reinforce Email Security Training
While patching addresses these specific vulnerabilities, new ones will emerge. Office documents remain one of the most common malware delivery mechanisms, precisely because they’re ubiquitous in business environments. Reinforce your email security training to emphasise:
- Scrutinising unexpected attachments, even from known senders (compromised accounts are common)
- Verifying requests via a separate communication channel before opening financial documents or contracts
- Understanding that Preview Pane can trigger exploits—seeing an email’s content in the preview doesn’t make it safe
- Reporting suspicious emails to your IT team or provider immediately
Email security training isn’t a one-time checkbox exercise. The threat landscape evolves, and as we highlighted in our article on business email compromise, social engineering tactics become more sophisticated every year. Regular, scenario-based training is essential.
The Bigger Picture: Managing Vulnerability Fatigue
Traditional monthly patching schedules struggle to manage large-scale updates without risk-based prioritisation, and organisations should evaluate factors beyond CVSS scores, such as internet exposure, asset criticality, and known exploitation
, according to security experts analysing this month’s release.
The challenge for UK SMEs isn’t just applying this month’s Office patches—it’s building sustainable processes for handling the relentless pace of vulnerability disclosure and patching.
Cyber threats facing UK businesses in 2026 are evolving faster than security teams can adapt, with attackers using AI to generate convincing phishing attacks, exploit software supply chains, compromise cloud identities and launch highly disruptive ransomware campaigns
.
This month’s Office vulnerabilities sit within that broader threat landscape. They’re not isolated incidents but part of an accelerating cycle where AI tools help both defenders find vulnerabilities and attackers exploit them. For UK SMEs, the question isn’t whether to invest in proper IT security and patch management—it’s whether you can afford not to.
Take Action Today
The nine critical Office RCE vulnerabilities patched in July 2026 represent a clear and present danger to UK SMEs. The Preview Pane attack vector makes exploitation trivially easy, and the ubiquity of Office in business environments makes these applications high-value targets.
If you’re uncertain whether your Office installations are fully patched, whether your remote workers are protected, or whether your patch management process can handle the sustained high-volume environment we’re now operating in, it’s time to get expert help. Reactive IT support—fixing problems after they occur—is no longer sufficient when vulnerabilities are being discovered and exploited at this pace.
Meridian Micro provides comprehensive IT support and security services to SMEs across Kent and the South East, including proactive patch management, security audits, and 24/7 monitoring. We handle the complexity of modern IT security so you can focus on running your business. Call us today on 01303 883111 to discuss how we can protect your business from the latest threats, or visit our Firewalls & Security page to learn more about our security services.
