Junglewise Threat Intelligence

CVE-2026-55028: Microsoft Office out-of-bounds read information disclosure

CVE-2026-55028 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft SharePoint Server 2019, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Office and SharePoint products that could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. Successful exploitation could lead to the unauthorized disclosure of private data, potentially compromising user privacy or corporate confidentiality.

Technical details

This vulnerability is classified as an out-of-bounds read (CWE-125) within Microsoft Office and SharePoint Server components. The flaw is triggered when the application reads data past the end of the intended buffer while processing a malicious file. An attacker can exploit this by convincing a user to open a crafted document, leading to the disclosure of sensitive information from the process memory. The attack vector is local, requiring user interaction, and carries a high confidentiality impact but no impact on integrity or availability. Microsoft has released security updates to address this issue across affected versions of Office 365, LTSC, and SharePoint.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft Microsoft SharePoint Server 2019 16.0.0 to latest security release

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats