Microsoft patched a security vulnerability in the remastered version of Age of Empires II in July 2026 that could have allowed hackers to take over a victim’s computer by sending a malicious game invite.
The flaw, tracked as CVE-2026-50663, was among a record number of security bugs Microsoft fixed on Patch Tuesday, July 15, 2026. According to the company, the high volume of fixes was driven in part by the use of AI to help Microsoft and external researchers identify vulnerabilities.
The Age of Empires II bug was identified and detailed by cybersecurity firm Rapid7. A successful attack would have allowed a hacker to place malicious files on a victim’s computer, ultimately enabling remote code execution — effectively giving the attacker control of the targeted machine. Security researcher Rick de Jager posted a video on X demonstrating how the exploit works, showing that a victim simply needed to join an attacker’s lobby and accept user-created content for the attack to succeed.
Age of Empires II, originally released 25 years ago, remains an active game in its remastered form. There is no evidence the vulnerability was exploited in the wild before the patch was issued.
The bug highlights a broader risk associated with online gaming. Targeting video game players could be an effective method for spreading malware across a large number of computers and stealing user credentials, according to the source material. Players who have not yet applied the latest Microsoft updates may want to do so promptly to ensure they are protected.
Source: TechCrunch