Description
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in Microsoft Office that permits an unauthenticated attacker to exfiltrate sensitive information across a network. The flaw arises when the application processes data that exceeds expected bounds, exposing memory contents that may contain credentials, personal data, or other confidential material. The impact is the potential for a data breach that could compromise user privacy and regulatory compliance.

Affected Systems

Affected installations include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024.

Risk and Exploitability

The CVSS score of 6.5 categorizes the risk as moderate, and there is currently no EPSS score reported or presence in the CISA KEV catalog. Although no known exploits are documented as of the latest advisory, the ability to read arbitrary memory makes the vulnerability attractive for adversaries seeking to gather sensitive data. The attack vector is inferred to be remote, requiring an attacker to deliver malicious input to the Office process over the network. Mitigation requires immediate application of vendor updates, as earlier remediation is not available.

Generated by OpenCVE AI on September 9, 2026 at 02:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Microsoft Office security update that addresses CVE‑2026‑80076 for all affected versions.
  • Limit network exposure of Office components by restricting inbound connections through firewalls or network segmentation whenever feasible.
  • Monitor system logs and network traffic for indicators of data exfiltration, and conduct a review of recent documents for potential leaked content.

Generated by OpenCVE AI on September 9, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Title Microsoft Office Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:27.592Z

Reserved: 2026-08-25T18:37:59.828Z

Link: CVE-2026-80076

cve-icon Vulnrichment

Updated: 2026-09-08T20:01:03.702Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:49.723

Modified: 2026-09-17T20:18:34.407

Link: CVE-2026-80076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T00:45:05Z

Weaknesses