Microsoft patches bug in video game Age of Empires II

Microsoft has released a security patch for the 25-year-old game Age of Empires II to fix a remote code execution vulnerability. The bug could have allowed attackers to take control of a user's computer through malicious game invites, though no evidence of exploitation exists.
Why it matters
This highlights the ongoing security risks in legacy software and the importance of automated bug detection in maintaining cybersecurity for widely used applications.
On Tuesday, Microsoft patched a historic record number of security bugs across its product lines, in large part due to the use of AI to help the company and external researchers to discover bugs.
Among the fixed vulnerabilities there was one for the remastered version of the classic 25-year-old war strategy video game Age of Empires II. The flaw allowed hackers to take over a victim’s computer by sending a custom malicious game invite, according to security researchers.
A video posted on X shows how the flaw could be exploited by hackers.
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution. pic.twitter.com/QmMkY07C8S
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in