Type Confusion Vulnerability in Microsoft Office Software
CVE-2026-26110
8.4HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-26110?
A type confusion vulnerability exists in Microsoft Office that may allow an unauthorized attacker to execute arbitrary code on affected installations. This flaw occurs when the software incorrectly handles resource types, leading to a breach of security protocols. Users are recommended to apply the latest security updates provided by Microsoft to mitigate the risks associated with this vulnerability.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Office 2016 32-bit Systems 16.0.0 < 16.0.5543.1000
Microsoft Office 2019 32-bit Systems 19.0.0