Summary
Microsoft Word has a use-after-free in its document handling code that can let an attacker execute code locally on a victim machine. Microsoft’s May 2026 security updates cover Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, Office for Mac 2021/2024, and Word 2016. The flaw can be triggered by malicious documents or previewed content and does not require authentication, and successful exploitation runs attacker-controlled code in the Word/Office process under the current user context.
Why Planned Fix?
5/6Exploitation Details
Execute arbitrary code as the current user
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Microsoft 365 Apps for Enterprise | 16.0.1 through the May 12, 2026 Office security release |
| Microsoft Office 2019 | 19.0.0 through the May 12, 2026 Office security release |
| Microsoft Office LTSC 2021 | 16.0.1 through the May 12, 2026 Office security release |
| Microsoft Office LTSC 2024 | 16.0.0 through the May 12, 2026 Office security release |
| Microsoft Office LTSC for Mac 2021 | 16.0.1 through 16.109.26051019 |
| Microsoft Office LTSC for Mac 2024 | 16.0.0 through 16.109.26051019 |
| Microsoft Word 2016 | 16.0.1 through 16.0.5552.1000 |
Microsoft Word is Microsoft’s word-processing application for creating, editing, and reviewing documents, and is commonly deployed as part of Microsoft Office and Microsoft 365.
Affected ComponentWord's document parsing and rendering code path, including preview handling when documents are rendered in Office or Outlook.
Word's document parsing and rendering code path, including preview handling when documents are rendered in Office or Outlook.
Not available
Not available
Install the May 12, 2026 Microsoft Office security updates. Word 2016 users should apply KB5002858, and Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, and Office for Mac 2021/2024 should move to the corresponding May 12, 2026 builds listed in Microsoft’s release notes.
Install the May 12, 2026 Microsoft Office security updates. Word 2016 users should apply KB5002858, and Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, and Office for Mac 2021/2024 should move to the corresponding May 12, 2026 builds listed in Microsoft’s release notes.
Probability of exploitation in the next 30 days
Worse than 18% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| learn.microsoft.com | Release notes for Microsoft Office security updates |
| learn.microsoft.com | Release notes for Office for Mac |
| support.microsoft.com | Word 2016 security update KB5002858 |
| vulnerability.circl.lu | CVE-2026-40361 vulnerability lookup |
| www.tenable.com | CVE-2026-40361 |
| www.securityweek.com | Microsoft patches critical zero-click Outlook vulnerability threatening enterprises |
Priority History
Initial analysis
Elevated — new exploitation evidence confirmed