VDB

CVE-2026-40363

CVE-2026-40363 PUBLISHED CVSS 8.399999618530273 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

EPSS 0.06% · 18.2th percentile

Risk Scores

CVSS 3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
0.06%
18.2th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Office 201919.0.0, 19.0.0, 19.0.0
MicrosoftMicrosoft Office for Android16.0.1, 16.0.1, 16.0.1
MicrosoftMicrosoft Office LTSC for Mac 202116.0.1, 16.0.1, 16.0.1
MicrosoftMicrosoft Office LTSC 202116.0.1, 16.0.1, 16.0.1
MicrosoftMicrosoft Office LTSC 202416.0.0, 16.0.0, 16.0.0
microsoftoffice_macos_202116.0.1, 16.0.1, 16.0.1
microsoftoffice_202116.0.1, 16.0.1, 16.0.1
microsoftoffice_202416.0.0, 16.0.0, 16.0.0
MicrosoftMicrosoft Office 201616.0.0, 16.0.0, 16.0.0
microsoft365_apps16.0.1, 16.0.1, 16.0.1
MicrosoftMicrosoft Office LTSC for Mac 202416.0.0, 16.0.0, 16.0.0
microsoftoffice16.0.1, 16.0.1, 16.0.1
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1, 16.0.1, 16.0.1
microsoftoffice_macos_202416.0.0, 16.0.0, 16.0.0
microsoftoffice_201919.0.0, 19.0.0, 19.0.0
microsoftoffice_201616.0.0, 16.0.0, 16.0.0

Timeline

  • May 12, 2026 CVE Published
  • May 12, 2026 PoC Published
  • May 12, 2026 PoC Published
  • May 13, 2026 PoC Published
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory

References

…and 2 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›