Microsoft released a record number of security patches on Tuesday, aided significantly by AI tools that helped both the company and external researchers identify vulnerabilities. One notable fix addressed a flaw in the remastered edition of the 25-year-old strategy game Age of Empires II.
The vulnerability, tracked as CVE-2026-50663, permitted remote code execution. An attacker could send a custom malicious game invite; once the victim joined the lobby and auto-accepted a user-created game, the attacker gained the ability to run arbitrary code on the target machine. Security researcher Rick de Jager demonstrated the exploit in a video posted on X.
Cybersecurity firm Rapid7 explained that a successful attack would let hackers drop malicious files onto the victim’s computer and ultimately seize full control. No evidence indicates the bug was exploited in the wild prior to the patch. Still, experts observe that video-game communities remain attractive targets for malware campaigns aimed at credential theft and large-scale infections.
The Age of Empires II fix formed part of Microsoft’s broader Patch Tuesday effort covering numerous products and underscores the growing role of AI in accelerating vulnerability discovery and remediation.