Description
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

Microsoft Office contains a flaw where an uninitialized resource can be read by an unauthorized user, enabling the disclosure of sensitive information over a network. The vulnerability is classified as CWE-908 and carries a CVSS score of 6.5, indicating moderate severity. The description states that the exposure occurs when no proper initialization occurs, allowing an attacker to access internal data that should not be transmitted.

Affected Systems

The flaw affects a broad set of Office products, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 2021, Office 2024, Office 365 for Mac, Office LTSC 2021, Office 2024, and the corresponding Mac editions. All listed versions are impacted; no specific version numbers are provided, so any current installation of these products may be vulnerable.

Risk and Exploitability

The EPSS score is unavailable, but the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a known high‑profile exploit. The likely attack vector is remote, requiring an attacker to communicate with the Office application over a network, such as a corporate VPN or local network. Because the flaw allows data disclosure, an attacker could gain access to confidential documents or personal information. Given the moderate CVSS, the risk is significant enough to warrant patching, but the exploit’s feasibility may be limited by network defenses.

Generated by OpenCVE AI on September 9, 2026 at 02:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Microsoft Office security update that contains the fix for CVE‑2026‑80091.
  • Deploy the update through Windows Update, Microsoft Endpoint Manager, or your organization’s patch‑management system.
  • Use network segmentation or firewall rules to restrict Office applications to trusted internal networks, reducing exposure from external attackers.

Generated by OpenCVE AI on September 9, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office 2016
Microsoft microsoft Office 2019
Microsoft microsoft Office 365 For Mac
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024
Vendors & Products Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office 2016
Microsoft microsoft Office 2019
Microsoft microsoft Office 365 For Mac
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Title Microsoft Office Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-908
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Microsoft 365 Apps For Enterprise Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 For Mac Microsoft Office Ltsc 2021 Microsoft Office Ltsc 2024 Microsoft Office Ltsc For Mac 2021 Microsoft Office Ltsc For Mac 2024 Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:32.686Z

Reserved: 2026-08-25T18:37:59.829Z

Link: CVE-2026-80091

cve-icon Vulnrichment

Updated: 2026-09-08T20:00:00.719Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:51.680

Modified: 2026-09-17T20:18:36.057

Link: CVE-2026-80091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:45:15Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource