Use After Free Vulnerability in Microsoft Office Word
CVE-2026-40361
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 May 2026
Badges
What is CVE-2026-40361?
CVE-2026-40361 is a critical vulnerability identified within Microsoft Office Word, a widely used word processing software essential for document creation and editing across various industries. This specific flaw manifests as a use after free vulnerability, which occurs when a program continues to use memory after it has been freed, potentially allowing attackers to execute arbitrary code on the affected system. The implications are significant; organizations relying on Microsoft Office Word for documentation could find their systems compromised, leading to unauthorized control, data breaches, and severe operational disruptions.
Potential impact of CVE-2026-40361
-
Unauthorized Code Execution: The vulnerability enables attackers to execute malicious code locally, which can result in total system compromise. This means that sensitive data could be accessed or manipulated without the consent of the user.
-
Data Breaches: Exploiting this vulnerability could lead to the leak of confidential information, including intellectual property and personal data, thereby violating data protection regulations and impacting organizational reputation.
-
Operational Disruption: Successful exploitation might disrupt business operations, leading to downtime and potential financial losses due to the remediation efforts required to secure the affected systems and recover from the attack.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Office 2019 32-bit Systems 19.0.0
Microsoft Office LTSC 2021 32-bit Systems 16.0.1
News Articles
Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises
Microsoft patches a critical Outlook vulnerability tracked as CVE-2026-40361 that can be exploited for remote code execution.
3 weeks ago
References
CVSS V3.1
Timeline
- π
Vulnerability started trending
- πΎ
Exploit known to exist
- π°
First article discovered by Securityweek
Vulnerability published
Vulnerability Reserved