CVE-2026-81952: Microsoft Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Word Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20896 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1003Patch KB5002916 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20204
Event History
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
The attacker must cause a user to interact with malicious content. The vulnerability is reachable over a network and does not require the attacker to authenticate or hold privileges on the target system.
Which deployments are in scope?
The affected software list includes Microsoft 365 Apps for Enterprise; Microsoft Office 2016; Office LTSC 2021 and 2024 for 32-bit and 64-bit editions; and Office LTSC for Mac 2021 and 2024.
What is the potential impact if exploitation succeeds?
Successful exploitation allows code execution and is rated High with a CVSS score of 8.8. The supplied vector indicates high potential impact to confidentiality, integrity, and availability.