CVE-2026-44821: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Patch KB5002878 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20153Patch KB5002876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20384Patch KB5002873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Fixed in 16.0.5556.1002Patch KB5002881
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44821?
The severity of CVE-2026-44821 is medium with a score of 5.5.
How do I fix CVE-2026-44821?
To fix CVE-2026-44821, ensure that you apply the latest security updates provided by Microsoft for the affected software.
Which Microsoft products are affected by CVE-2026-44821?
CVE-2026-44821 affects Microsoft Office 2016, Microsoft SharePoint Server, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, and Microsoft Office LTSC for Mac 2021.
What type of vulnerability is CVE-2026-44821?
CVE-2026-44821 is classified as an information disclosure vulnerability due to an out-of-bounds read in Microsoft Office.
What can an attacker do with CVE-2026-44821?
An attacker exploiting CVE-2026-44821 can disclose sensitive information locally without authentication.