<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:microsoft:graphic_fonts:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftgraphic_fonts/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 20:37:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftgraphic_fonts/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Graphic Fonts Component</title><link>https://feed.craftedsignal.io/briefs/2026-09-graphic-fonts-rce/</link><pubDate>Tue, 08 Sep 2026 20:37:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-graphic-fonts-rce/</guid><description>CVE-2026-72986 describes a heap-based buffer overflow vulnerability within the Graphic Fonts component allowing unauthenticated remote code execution over a network.</description><content:encoded><![CDATA[<p>Microsoft has disclosed a critical heap-based buffer overflow vulnerability identified as CVE-2026-72986 affecting the Graphic Fonts component. This vulnerability is classified as remote code execution, enabling an unauthorized attacker to send specially crafted data over a network to the target system. Successful exploitation results in the attacker executing arbitrary code within the context of the affected process. As this component handles font rendering, it is frequently invoked when processing documents, images, or web content containing embedded fonts. Defenders should prioritize patching systems where this component is active, as the ability to trigger the overflow remotely without authentication presents a significant risk for lateral movement or initial system compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-72986 allows unauthenticated attackers to gain remote code execution on the target host. This can lead to full system compromise, data exfiltration, or the deployment of secondary malicious payloads within the targeted network environment. Organizations using Windows environments where the Graphic Fonts component parses untrusted or external data are at the highest risk.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize applying the relevant security updates provided by Microsoft for CVE-2026-72986 across all Windows systems. Ensure automated patch management systems are configured to deploy security-only updates to mitigate this vulnerability. If patching cannot be performed immediately, restrict network access to the affected systems from untrusted zones to reduce the attack surface for remote exploitation.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>