Microsoft disclosed two critical Windows Graphics Component remote code execution vulnerabilities, CVE-2026-44812 and CVE-2026-44803, both tied to integer overflow or wraparound issues in Windows Win32K-GRFX. The flaws can let an unauthorized attacker execute code locally if a user views a specially crafted file in the Windows File Explorer Preview Pane or opens the file directly. Microsoft rated both issues CVSS 7.8, said exploitation is more likely, and reported that neither vulnerability had been publicly disclosed or exploited at the time of publication.
Microsoft said official fixes are available for the Windows issues, while updates for Microsoft Word for Android, Microsoft PowerPoint for Android, and Microsoft Excel for Android were not yet available and will be released later through revised advisories. The company credited Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab, Seung Chan Kim, and SnowRockLab for reporting CVE-2026-44812; the related advisory for CVE-2026-44803 similarly noted pending Android app updates and high impact to confidentiality, integrity, and availability.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2026-44812, a critical Windows Graphics Component remote code execution vulnerability in Windows Win32K-GRFX, and stated that an official fix is available. Microsoft also noted the issue had not been publicly disclosed or exploited at publication and credited KAIST Hacking Lab, Seung Chan Kim, and SnowRockLab for reporting it.
Microsoft disclosed CVE-2026-44803, a critical Windows Graphics Component remote code execution vulnerability in Windows Win32K-GRFX, and indicated that an official fix is available. The company said exploitation was considered more likely, but the flaw was not publicly disclosed or observed exploited at publication.
Microsoft published its Security Update Guide entry for CVE-2021-28349, a Windows GDI+ remote code execution vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.