Insufficiently protected credentials in Microsoft Office - CVE-2026-64918
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose NTLM hashes.
The vulnerability exists due to insufficiently protected credentials in Microsoft Office when a user interacts with a file. A remote attacker can induce a user to interact with a file to disclose NTLM hashes.
Interactions that trigger the leakage include opening the parent folder in Explorer, clicking, dragging, or deleting the file.