CVE-2026-50314: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1000Patch KB5002887 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50314?
CVE-2026-50314 is rated as high severity with a score of 7.8.
How do I fix CVE-2026-50314?
To address CVE-2026-50314, update your Microsoft Office applications to the latest version provided by Microsoft.
What is CVE-2026-50314?
CVE-2026-50314 is a Microsoft Office Remote Code Execution Vulnerability caused by a use after free condition.
Which software is affected by CVE-2026-50314?
CVE-2026-50314 affects Microsoft Office 2016, Microsoft 365 Apps, Office 2019, 2021, 2024, and Office LTSC 2024.
Can CVE-2026-50314 be exploited remotely?
CVE-2026-50314 allows unauthorized attackers to execute code locally, but user interaction is required for the exploit.