Junglewise Threat Intelligence

CVE-2026-55139: Microsoft Office out-of-bounds read

CVE-2026-55139 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in several versions of Microsoft Office, including Office 365 and LTSC editions. An attacker could exploit this flaw to gain unauthorized access to information stored on a user's local computer. To be successful, an attacker would typically need to convince a user to open a specially crafted file.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office across multiple versions for both Windows and Mac. The flaw is triggered when the application processes a malformed file, leading to memory access outside of the intended buffer. An attacker can exploit this locally to disclose sensitive information from the system's memory. Exploitation requires user interaction, specifically that a user opens a malicious file provided by the attacker. Microsoft has released security updates to address this issue across the affected product lines.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record
  • 2026-07-14: advisory: Microsoft released security update details

References

Related threats