Junglewise Threat Intelligence

CVE-2026-66809: Microsoft Office out-of-bounds read information disclosure

CVE-2026-66809 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office contains an out-of-bounds read vulnerability that allows a local attacker to read sensitive information from memory. An attacker with local access to a system running vulnerable Office software could exploit this to access confidential data, such as credentials or document contents, without authorization.

Technical details

This vulnerability is an out-of-bounds read in Microsoft Office, a memory safety issue where the application reads data beyond the bounds of an allocated buffer. The vulnerability requires local access to the affected system and allows an unauthenticated attacker to disclose information resident in memory. The attack vector is local, meaning the attacker must have code execution capability or local system access. Microsoft has released patches to address this issue as indicated by the CVE disclosure.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats