CVE-2026-35440
published 2026-05-12CVE-2026-35440: Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
PriorityP428medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.45%
36.6th percentile
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5552.1000 | 16.0.5552.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | word | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Word up to Word 2016 file access
vuldb·2026-05-12
CVE-2026-35440 [LOW] Microsoft Word up to Word 2016 file access
A vulnerability identified as problematic has been detected in Microsoft Word 2019/365 Apps/LTSC 2021/LTSC 2024/Word 2016. This issue affects some unknown processing. This manipulation causes files or directories accessible.
The identification of this vulnerability is CVE-2026-35440. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-m7q8-mvmc-97p3: Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally
ghsa_unreviewed·2026-05-12
CVE-2026-35440 [MEDIUM] CWE-552 GHSA-m7q8-mvmc-97p3: Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
No detection rules found.
No public exploits indexed.
2026-05-12
Published