CVE-2026-40366: Microsoft Word Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Word Remote Code Execution Vulnerability
— Microsoft
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1000Patch KB5002858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.109.26051019
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40366?
CVE-2026-40366 has a severity rating of high, with a score of 8.4.
What impact does CVE-2026-40366 have on my system?
CVE-2026-40366 allows an unauthorized attacker to execute code locally on affected Microsoft Word applications.
How do I fix CVE-2026-40366?
To fix CVE-2026-40366, you should apply the latest security updates provided by Microsoft for the affected software.
Which Microsoft products are affected by CVE-2026-40366?
CVE-2026-40366 affects Microsoft Office Long Term Servicing Channel, Microsoft Word 2016, and Microsoft 365 Apps.
Is it safe to use Microsoft Word with CVE-2026-40366 vulnerability?
Using Microsoft Word with CVE-2026-40366 poses a risk of remote code execution, so it is recommended to update immediately.