CVE-2026-20943 PUBLISHED

Multiple Microsoft Office products contain the following vulnerability.<ul><li>Untrusted search path (CWE-426, - CVE-2026-20943</li></ul>Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

EPSS 0.05% · 14.5th percentile

Risk Scores

EPSS Score
0.05%
14.5th percentile

Affected Products

VendorProductVersions
Microsoft CorporationMicrosoft Office
Microsoft CorporationOffice Deployment Tool
Microsoft CorporationMicrosoft SharePoint Server
Microsoft CorporationMicrosoft SharePoint Enterprise Server

Timeline

References

Open in Interactive Console →