Junglewise Threat Intelligence

CVE-2026-72976: Microsoft Office Word out-of-bounds read

CVE-2026-72976 · Severity: medium · CVSS 5 · Published 2026-09-08

Executive brief

Microsoft Office Word is a widely-used word processing application found in most corporate environments. This vulnerability allows an authorized attacker with local access to read sensitive information from memory that should not be accessible, potentially exposing confidential document content or system data.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Word that allows an authorized local attacker to disclose sensitive information. The vulnerability requires local system access and the attacker must be already authorized on the target system. By exploiting this flaw, an attacker can read memory regions outside the intended bounds of a data structure, potentially exposing confidential information from the application's memory space. The CVSS score of 5.0 indicates medium severity with limited impact scope.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats