<< Back
CVE Number Vulnerability Product Severity Date
CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Critical 29-05-2026

Technical Information

An unauthorized attacker could exploit heap-based buffer overflow to perform remote code execution by sending a malicious office file and convince them to open it.

Patch release date: May 12, 2026
Further information on this vulnerability is available at : CVE-2026-42831

Affected Software

Microsoft Office LTSC for Mac 2021,
Microsoft Office for Android,
Microsoft Office LTSC for Mac 2024