CVE-2026-35440: Microsoft Word Information Disclosure Vulnerability
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Word Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1000Patch KB5002858
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35440?
CVE-2026-35440 has a medium severity rating of 5.5.
How do I fix CVE-2026-35440?
To fix CVE-2026-35440, update Microsoft Word and the associated Microsoft Office applications to the latest version.
What impact does CVE-2026-35440 have on users?
CVE-2026-35440 allows unauthorized attackers to disclose sensitive information from files or directories in Microsoft Word.
Which Microsoft products are affected by CVE-2026-35440?
CVE-2026-35440 affects Microsoft Office Long Term Servicing Channel, Microsoft 365 Apps for Enterprise, and various versions of Microsoft Word.
When was CVE-2026-35440 published?
CVE-2026-35440 was published on May 12, 2026.