Junglewise Threat Intelligence

CVE-2026-55022: Microsoft Office type confusion code execution

CVE-2026-55022 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to run unauthorized code on a user's computer if the user is tricked into opening a specially crafted file. This could lead to a full system compromise, allowing the attacker to steal sensitive data, install malware, or disrupt business operations.

Technical details

A type confusion vulnerability (CWE-843) exists in Microsoft Office due to the application incorrectly processing resources using incompatible types. The vulnerability is triggered when a user opens a maliciously crafted Office document. While the attack vector is classified as local, it requires user interaction (UI:R) to execute. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user, potentially leading to a complete compromise of confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across various Office versions, including Office 2016, 2019, LTSC, and Microsoft 365 Apps.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215

Timeline

  • 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
  • 2026-07-14: advisory: Microsoft released security update guide for CVE-2026-55022.

References

Related threats