Type Confusion in Microsoft 365 Apps for Enterprise and Microsoft Office - CVE-2026-72938
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to access of a resource using an incompatible type in Microsoft Office PowerPoint when processing PowerPoint content. A remote attacker can cause PowerPoint to process content to disclose information.
The Preview Pane is not an attack vector.
Affected software
Microsoft Office
How to mitigate CVE-2026-72938
Microsoft Office - addressed in versions 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976