CVE-2026-32190

CWE-416Use After Free4 documents4 sources
Severity
8.4HIGH
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14

Description

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages7 packages

CVEListV5microsoft/microsoft_office_201616.0.016.0.5548.1000
CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_202116.0.1https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_202416.0.0https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_for_mac_202116.0.116.108.26041219

🔴Vulnerability Details

2
CVEList
Microsoft Office Remote Code Execution Vulnerability2026-04-14
VulDB
Microsoft Office 2016/2019/LTSC/LTSC 2021/LTSC 2024 use after free2026-04-14
CVE-2026-32190 (HIGH CVSS 8.4) | Use after free in Microsoft Office | cvebase.io