Jul 2026: Microsoft Word Information Disclosure Vulnerability
CVE-2026-55124 Published on July 14, 2026

Microsoft Word Information Disclosure Vulnerability
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Vendor Advisory NVD

Weakness Types

Improper Validation of Specified Type of Input

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Products Associated with CVE-2026-55124

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Microsoft 365 Apps for Enterprise: Microsoft Office 2019: Microsoft Office 365 for Mac: Microsoft Office LTSC 2021: Microsoft Office LTSC 2024: Microsoft Office LTSC for Mac 2021: Microsoft Office LTSC for Mac 2024: Microsoft SharePoint Enterprise Server 2016: Microsoft SharePoint Server 2019: Microsoft SharePoint Server Subscription Edition: Microsoft Word 2016: