CVE-2026-40361: Microsoft Outlook and Word Remote Code Execution Vulnerability
Microsoft Outlook and Word Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1000Patch KB5002858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.109.26051019
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40361?
The severity of CVE-2026-40361 is rated high with a score of 8.4.
How do I fix CVE-2026-40361?
To mitigate CVE-2026-40361, apply the latest security updates and patches provided by Microsoft for affected versions of Microsoft Word.
What types of software are affected by CVE-2026-40361?
CVE-2026-40361 affects Microsoft Office Long Term Servicing Channel, Microsoft Word 2016, Microsoft 365 Apps for Enterprise, and other versions of Microsoft Office.
What is the impact of CVE-2026-40361?
CVE-2026-40361 allows an unauthorized attacker to execute code locally through a use after free vulnerability in Microsoft Word.
When was CVE-2026-40361 published?
CVE-2026-40361 was published on May 12, 2026.