Microsoft has published CVE-2026-70310, a Microsoft Word information disclosure vulnerability, but the public record as of August 12 provides far less operational detail than administrators normally need to prioritize a document-handling flaw. The Microsoft Security Response Center entry was published on August 11, 2026 at 7:00 a.m. Pacific time, and it identifies Word and the confidentiality impact category; it does not, in the material currently exposed, establish a CVSS score, affected Word builds, a specific update package, or a public exploitation report.

That absence changes the immediate task. This is a patch-verification issue for organizations running desktop Word, not evidence that every Microsoft 365 tenant, Office installation, or Windows PC faces the same exposure. Security teams should ensure that Word is receiving its August 2026 security servicing through the channel applicable to that installation, then inventory the versions that cannot be brought current.

An IT professional monitors patch compliance and a critical Microsoft Word vulnerability across multiple devices.Microsoft has confirmed the CVE, but not its practical scope​

Microsoft’s Security Update Guide is the authoritative record for CVE-2026-70310’s existence and its classification as an information disclosure issue in Microsoft Word. Microsoft’s publication date places the disclosure on the August 11 Patch Tuesday release cycle, but a CVE appearing on that date does not itself identify the delivery mechanism or every product edition covered by the fix.

The record supplied for this vulnerability includes explanatory text for CVSS’s Report Confidence metric. That text is a definition of what the metric means; it is not the metric’s assigned value for CVE-2026-70310. It should not be read as confirmation that proof-of-concept code exists, that an exploit has been independently reproduced, or that Microsoft has assigned a “Confirmed” confidence value to this particular vulnerability.

This distinction is easy to lose in automated vulnerability feeds. A scanner or dashboard may display a long explanation of a CVSS field while leaving out the field’s actual value. For CVE-2026-70310, the material available here establishes that Microsoft assigned a CVE and calls the impact information disclosure. It does not disclose the malformed file type, Word parsing feature, prerequisite access, user interaction requirement, or the exact data that could be exposed.

No independent security reporting located for this specific CVE has filled in those gaps so far. That is normal on the first day of a monthly release, especially for Office vulnerabilities where Microsoft often keeps technical details limited while updates propagate. It is also a reason to avoid escalating this entry into a “zero-click Word bug” or a remotely exploitable issue without evidence.

Information disclosure does not mean remote code execution​

“Information disclosure” is a bounded impact category. A successful exploit may expose data that should remain unavailable to an attacker, but Microsoft has not publicly described what information CVE-2026-70310 could reveal or how an attacker would obtain it. It should not be described as a code-execution vulnerability, a privilege-escalation flaw, or a bypass of Word’s macro protections unless Microsoft or subsequent technical research says so.

For document-driven vulnerabilities, exploitation often depends on delivery and user behavior: a victim may have to open a malicious document, enable content, interact with a file hosted on a share, or use a particular Office component. Those are examples of common Office attack paths, not confirmed conditions for this CVE. Microsoft has not published enough detail to say which, if any, apply here.

The conservative reading is therefore straightforward: if an attacker can meet Microsoft’s undisclosed conditions, the flaw could permit unauthorized disclosure of information handled by Word. For enterprises, that can still carry material consequences where documents contain customer data, contracts, internal reports, legal communications, financial forecasts, source code, or credentials copied into text.

The lack of a published severity score also means administrators should not substitute a guess. A low confidentiality impact in CVSS terms can still matter greatly when the affected workstation belongs to a finance executive, legal team, administrator, developer, or employee with access to sensitive shared locations. Conversely, a broad but user-interaction-dependent flaw may be a different deployment priority from an actively exploited network vulnerability. Microsoft has not yet supplied enough public information to make that calculation precisely.


Word updates must be checked separately from Windows updates​

The practical risk is that organizations treat Patch Tuesday as a single Windows servicing event. CVE-2026-70310 affects Word, and Word can be serviced through different mechanisms depending on the Office edition and installation type. Applying the August Windows cumulative update alone is not reliable proof that a desktop Office security fix has arrived.

Microsoft 365 Apps installations generally receive Word fixes through their configured Office update channel. Those deployments should be checked using the Office version and build information reported by the client and the organization’s selected servicing channel, rather than by the Windows OS build alone. Administrators using Current Channel, Monthly Enterprise Channel, Semi-Annual Enterprise Channel, or a managed update platform should verify that the applicable August Office build has actually reached devices.

Perpetual Office editions and legacy MSI-based installations need a separate review. They may receive standalone Office security updates, but only while the particular edition remains in support and Microsoft has issued an update for it. The CVE record needs to be consulted for the final product-and-KB mapping once Microsoft’s supporting update documentation is fully available.

The operational checks should be simple but specific:

  • Confirm that Microsoft 365 Apps devices have installed the approved August 2026 Office build for their assigned update channel.
  • Confirm that managed deployment tools have synchronized Office updates as well as Windows quality updates.
  • Identify Word installations that are disconnected from Office servicing, pinned to obsolete update channels, or unable to update because of unsupported operating systems or Office versions.
  • Preserve an exception list for systems where Word must remain installed but cannot be patched, then restrict untrusted document handling on those endpoints.

This last point is more important than it sounds. A workstation can be fully patched at the Windows layer while its Office applications are behind because updates are deferred, disabled, blocked by a proxy, or managed by a separate product team.

Unsupported Office is the enduring exposure​

Office 2016 reached end of support on October 14, 2025. Organizations that retained Word 2016 past that date should not assume that an August 2026 security disclosure has a patch available for them, even if the technical flaw proves relevant to their installed version. Microsoft’s current support position makes migration or compensating controls the realistic answer for those endpoints, not waiting for a new standalone fix.

Microsoft 365 Apps remain a different case. Microsoft has said it will continue to provide Microsoft 365 security updates on Windows 10 through October 10, 2028, despite Windows 10 reaching end of support on October 14, 2025. That gives organizations with supported Microsoft 365 Apps a path to remediate Word vulnerabilities while completing Windows 11 migrations, though it does not restore operating-system support or eliminate other Windows 10 risks.

For high-risk users, controls around document intake remain worthwhile while the technical details are sparse. Email gateways should continue blocking known malicious attachment types and links; Microsoft Defender for Office 365, endpoint protection, and Attack Surface Reduction policies should be verified rather than assumed; and users who receive untrusted documents should use Protected View and avoid opening attachments from unexpected senders. These are defense-in-depth measures, not Microsoft-designated mitigations for CVE-2026-70310.

Microsoft’s August 11 publication creates a clear action item: make sure supported Word installations receive the August Office security update appropriate to their servicing model. Until Microsoft adds affected builds, update identifiers, and exploitability details—or independent researchers document the flaw—the responsible conclusion is narrower: CVE-2026-70310 is a confirmed Microsoft Word security advisory whose public technical record is still incomplete.