CVE-2026-26110

HIGH

Microsoft Office - Memory Corruption

Title source: llm
STIX 2.1

Description

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Scores

CVSS v3 8.4
EPSS 0.0007
EPSS Percentile 21.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-843
Status published
Products (14)
microsoft/365_apps (2 CPE variants)
Microsoft/Microsoft 365 Apps for Enterprise 16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office 2016 16.0.0 - 16.0.5543.1000
Microsoft/Microsoft Office 2019 19.0.0 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office for Android 16.0.1 - 16.0.19822.20000
Microsoft/Microsoft Office LTSC 2021 16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office LTSC 2024 16.0.0 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office LTSC for Mac 2021 16.0.1 - 16.107.26030819
Microsoft/Microsoft Office LTSC for Mac 2024 16.0.0 - 16.107.26030819
microsoft/office 2016 (2 CPE variants)
... and 4 more
Published Mar 10, 2026
Tracked Since Mar 11, 2026