CVE-2026-40364: Microsoft Word Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Word Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.109.26051019 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1000Patch KB5002858
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40364?
CVE-2026-40364 has a severity rating of high at 8.4.
How do I fix CVE-2026-40364?
To fix CVE-2026-40364, ensure that you apply the latest security updates provided by Microsoft for affected versions of Microsoft Word.
What type of vulnerability is CVE-2026-40364?
CVE-2026-40364 is a Remote Code Execution vulnerability due to type confusion in Microsoft Word.
Which software is affected by CVE-2026-40364?
CVE-2026-40364 affects Microsoft Office Long Term Servicing Channel and various versions of Microsoft Word, including 2016 and 365 Apps.
Can CVE-2026-40364 be exploited remotely?
Yes, CVE-2026-40364 can be exploited locally by an unauthorized attacker to execute code.