Junglewise Threat Intelligence

CVE-2026-80089: Microsoft Office out-of-bounds read information disclosure

CVE-2026-80089 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office contains a vulnerability that allows an attacker to read memory outside the intended boundaries of an application, potentially exposing sensitive information. An attacker can exploit this flaw remotely to retrieve confidential data such as customer information, internal documents, or authentication credentials without proper authorization.

Technical details

This vulnerability is an out-of-bounds read flaw in Microsoft Office that enables information disclosure over a network. The vulnerability likely exists in document parsing or rendering logic that fails to properly validate buffer boundaries before reading memory. An attacker can craft a malicious Office document and send it to a target user, requiring user interaction (opening the document) to trigger the exploit. Successful exploitation allows the attacker to read arbitrary memory and disclose sensitive information from the affected process. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats