CVE-2026-40367: Microsoft Word Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Word Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1000Patch KB5002858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20128Patch KB5002872 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.109.26051019 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20280Patch KB5002863 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1002Patch KB5002869
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40367?
CVE-2026-40367 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-40367?
To fix CVE-2026-40367, ensure that you apply the latest security updates provided by Microsoft for the affected versions of Word and Office.
Which versions of Microsoft Word are affected by CVE-2026-40367?
CVE-2026-40367 affects multiple versions of Microsoft Word including Word 2016, Office LTSC 2021 and 2024, and Office 2019.
Can CVE-2026-40367 be exploited remotely?
Yes, CVE-2026-40367 can be exploited remotely by an attacker through untrusted pointer dereference.
What type of vulnerability is CVE-2026-40367?
CVE-2026-40367 is a remote code execution vulnerability that allows unauthorized execution of code via Microsoft Word.