cbcvebase.
CVE-2026-26113
published 2026-03-10

CVE-2026-26113: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2016>= 16.0.0 < 16.0.5543.100016.0.5543.1000
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2024>= 16.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_for_mac_2021>= 16.0.1 < 16.107.2603081916.107.26030819
microsoftmicrosoft_office_ltsc_for_mac_2024>= 16.0.0 < 16.107.2603081916.107.26030819
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5543.100016.0.5543.1000
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2010216.0.10417.20102
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.19725.2007616.0.19725.20076
microsoftoffice
microsoftoffice
microsoftoffice_long_term_servicing_channel
microsoftoffice_long_term_servicing_channel
microsoftsharepoint_server< 16.0.19725.2007616.0.19725.20076
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems
msrcmicrosoft_office_2016
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_office_ltsc_2021_for_64-bit_editions
msrcmicrosoft_office_ltsc_2024_for_32-bit_editions
msrcmicrosoft_office_ltsc_2024_for_64-bit_editions