Junglewise Threat Intelligence

CVE-2026-56195: Microsoft Office out-of-bounds read information disclosure

CVE-2026-56195 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Executive brief

A vulnerability in Microsoft Office could allow an attacker to access sensitive information on a user's computer. This issue affects various versions of Office, including Microsoft 365 Apps and LTSC editions on both Windows and Mac. To exploit this, an attacker would typically need to convince a user to open a specially crafted file, potentially leading to the exposure of private data or memory contents.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office. The flaw is triggered when the application fails to properly validate input, allowing a local attacker to read data outside the intended buffer. While the attack vector is local, it requires user interaction, such as opening a malicious document. Successful exploitation allows an attacker to disclose sensitive information from the process memory. Microsoft has released security updates to address this issue across affected Windows and Mac versions of Office.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to the July 2026 security updates
  • Microsoft Office 2016 versions prior to 16.0.5561.1000
  • Microsoft Office 2019 19.0.0 and later versions prior to the July 2026 security updates
  • Microsoft Office 365 for Mac versions prior to 16.111.26071215
  • Microsoft Office LTSC 2021 16.0.1 and later versions prior to the July 2026 security updates
  • Microsoft Office LTSC 2024 16.0.0 and later versions prior to the July 2026 security updates
  • Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
  • Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft released security updates and advisory.

References

Related threats