Use of uninitialized resource in Microsoft products - CVE-2026-80091
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to use of an uninitialized resource in Microsoft Office when processing content. A remote attacker can trigger processing that uses an uninitialized resource to disclose information.
The disclosed information may include uninitialized heap memory. The Preview Pane is an attack vector, and user interaction is required.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office
How to mitigate CVE-2026-80091
Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft Office - addressed in versions 16.0.5569.1000, 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976