CVE-2026-42832: Microsoft Office Spoofing Vulnerability
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.109.26051019 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19822.20190
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42832?
CVE-2026-42832 is classified as a moderate severity spoofing vulnerability in Microsoft Office.
How do I fix CVE-2026-42832?
To fix CVE-2026-42832, ensure your Microsoft Office applications are updated to the latest version available.
Which Microsoft Office products are affected by CVE-2026-42832?
Microsoft Office LTSC for Mac 2021 and 2024, as well as Excel and Word for Android, are affected by CVE-2026-42832.
Can CVE-2026-42832 be exploited remotely?
CVE-2026-42832 requires local access to exploit, so it cannot be exploited remotely.
What type of vulnerability is CVE-2026-42832?
CVE-2026-42832 is a spoofing vulnerability caused by improper access control in Microsoft Office.