Junglewise Threat Intelligence

CVE-2026-55129: Microsoft Office heap overflow remote code execution

CVE-2026-55129 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to run unauthorized code on a user's computer, potentially leading to full system takeover or data theft. This typically requires a user to open a specially crafted malicious file.

Technical details

A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Office, including Office 2016, 2019, LTSC, and Microsoft 365 Apps. The vulnerability is triggered when the application improperly handles memory during the processing of a malicious file. While the attack vector is local, it requires user interaction (UI:R), such as opening a booby-trapped document. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across affected platforms.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise >= 16.0.1
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 >= 19.0.0
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 >= 16.0.1
  • Microsoft Microsoft Office LTSC 2024 >= 16.0.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats