CVE-2026-40421: Microsoft Word Information Disclosure Vulnerability
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Word Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1000Patch KB5002858
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40421?
CVE-2026-40421 is categorized as an information disclosure vulnerability in Microsoft Word.
How do I fix CVE-2026-40421?
To fix CVE-2026-40421, update your Microsoft Word or Office applications to the latest security updates provided by Microsoft.
What software is affected by CVE-2026-40421?
CVE-2026-40421 affects various editions of Microsoft Office including LTSC 2024, 2021, Office 2019, and Word 2016.
How does CVE-2026-40421 impact users?
CVE-2026-40421 allows an unauthorized attacker to disclose sensitive information over a network.
Is there a patch for CVE-2026-40421?
Yes, Microsoft has released necessary security patches to address CVE-2026-40421 that users should apply immediately.