CVE-2026-64918: Microsoft Office Spoofing Vulnerability
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1003Patch KB5002916 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
Which Office deployments are listed as affected?
The listed products are Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Office 2019 for 32-bit and 64-bit editions, Office LTSC 2021 for 32-bit and 64-bit editions, and Office LTSC 2024 for 32-bit and 64-bit editions.
Does exploitation require an authenticated Office user or prior privileges?
No prior privileges are required (PR:N). The attack is network-based and requires user interaction (AV:N, UI:R).
What is the expected security impact if exploitation succeeds?
The vulnerability is rated medium severity with a 6.5 CVSS score. It has high confidentiality impact, while integrity and availability impact are rated none.