Safety

Microsoft fixes remote-code execution flaw in remastered Age of Empires II during large Patch Tuesday

On Patch Tuesday (July 15, 2026), Microsoft fixed a record number of security vulnerabilities across its products, assisted in part by AI.

Microsoft fixes remote-code execution flaw in remastered Age of Empires II during large Patch Tuesday

On July 15, 2026 — Patch Tuesday — Microsoft released fixes for a record number of security vulnerabilities across its product portfolio, citing the use of artificial intelligence as a factor that helped both the company and external researchers find bugs. One of the fixed flaws affected the remastered edition of the 25-year-old strategy game Age of Empires II.

What happened?

The vulnerability, tracked as CVE-2026-50663, could have allowed an attacker to seize control of a victim’s PC by sending a crafted malicious game invite. A short video posted on X demonstrated the exploitation: joining an attacker’s lobby, (auto-)accepting UCG (user-generated content), and triggering remote code execution.

Rapid7’s assessment

Cybersecurity firm Rapid7 said a successful exploit would permit an attacker to place malicious files on the victim’s machine, enabling execution of further malicious code — effectively allowing the attacker to take over the compromised computer.

Exploitation risk

Microsoft reported no evidence that the vulnerability was exploited in the wild. Nevertheless, security experts warn that targeting gamers can be an effective way to distribute malware: large numbers of users accept invites and share content, and a well-crafted malicious invite could lead to widespread infections or credential theft.

Recommended actions

Microsoft issued the patches as part of the July 15 Patch Tuesday; users and administrators are advised to install the updates. As additional precautions, disable automatic acceptance of UGC where possible and be cautious about accepting game invites from unknown sources.

Why this matters

The incident highlights multiple trends: traditional software bugs remain a serious risk, gaming platforms are an attractive attack surface for malware operators, and AI-assisted discovery is accelerating the identification of vulnerabilities — contributing to the unusually high number of fixes in this update cycle.


Key facts: CVE-2026-50663; Patch Tuesday date: July 15, 2026; sources: Microsoft Patch Tuesday release, Rapid7 analysis, demonstration by Rick de Jager on X.