Jul 2026: Microsoft Word Information Disclosure Vulnerability
CVE-2026-55124 Published on July 14, 2026
Microsoft Word Information Disclosure Vulnerability
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Weakness Types
Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Products Associated with CVE-2026-55124
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft 365 Apps for Enterprise:- Version 16.0.1 and below https://aka.ms/OfficeSecurityReleases is affected.
- Version 19.0.0 and below https://aka.ms/OfficeSecurityReleases is affected.
- Version 1.0.0 and below 16.111.26071215 is affected.
- Version 16.0.1 and below https://aka.ms/OfficeSecurityReleases is affected.
- Version 16.0.0 and below https://aka.ms/OfficeSecurityReleases is affected.
- Version 16.0.1 and below 16.111.26071215 is affected.
- Version 16.0.0 and below 16.111.26071215 is affected.
- Version 16.0.0 and below 16.0.5561.1001 is affected.
- Version 16.0.0 and below 16.0.10417.20175 is affected.
- Version 16.0.0 and below 16.0.19725.20434 is affected.
- Version 16.0.1 and below 16.0.5561.1000 is affected.