Junglewise Threat Intelligence

CVE-2026-64918: Microsoft Office insufficiently protected credentials spoofing

CVE-2026-64918 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office contains a vulnerability where credentials are not adequately protected, allowing an attacker to impersonate legitimate users or systems over a network. This could enable account takeover, unauthorized access to sensitive documents, or phishing campaigns that appear to come from trusted senders.

Technical details

A credential storage or transmission vulnerability in Microsoft Office allows insufficiently protected credentials to be accessed or manipulated by network-based attackers. The vulnerability enables spoofing attacks without requiring prior authentication or user interaction. While details are limited from the advisory sources, the attack vector is network-based and allows an attacker to impersonate legitimate Office users or sessions. Patches are expected to be available through Microsoft's standard security update channels.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats