Out-of-bounds read in Microsoft products - CVE-2026-80089
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office when a user interacts with the application. A remote attacker can cause the application to read out-of-bounds heap memory to disclose information.
Disclosed data may include small portions of heap memory.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office
How to mitigate CVE-2026-80089
Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft Office - addressed in versions 16.0.5569.1000, 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976