Microsoft has included CVE-2026-70314, a Microsoft Office information disclosure vulnerability, in its August 11, 2026 Office security release. The immediate action for administrators is straightforward: bring affected Microsoft 365 Apps, Office 2024, Office 2021, Office LTSC, and — unusually — Office 2019 installations to the August security builds identified by Microsoft rather than waiting for a more detailed technical write-up.

Microsoft’s Security Update Guide published the advisory at 7:00 a.m. Pacific time on August 11. Its Office security release notes independently place CVE-2026-70314 in the Office suite category, rather than under Word, Excel, Outlook, PowerPoint, or Access. That classification is operationally important: this is a suite-level fix, so an inventory limited to a single application executable or document handler can miss the affected deployment path.

Microsoft has not publicly described the vulnerable component, the attacker’s required access, the data that may be exposed, or a proof-of-concept technique. The published advisory title confirms the impact category — information disclosure — but does not establish whether the flaw is reachable through a malicious document, local content, a collaboration workflow, or another Office interaction. It also does not, in the material published with the advisory, provide a CVSS vector or an exploitation assessment that would let defenders distinguish a routine patch from one requiring immediate emergency rollout.

That absence does not make the update optional. It changes the way security teams should prioritize it: treat the August Office release as the remediation boundary, while avoiding unsupported claims that a crafted attachment, preview pane, macro, or remote attacker can exploit CVE-2026-70314. Microsoft has provided the fix; it has not provided enough public technical detail to responsibly reconstruct the attack chain.

IT professional monitoring an enterprise security dashboard showing Microsoft Office compliance and critical vulnerabilities.The August 11 builds are the practical fix line​

Microsoft’s Office security release notes identify the following August 11 builds for products covered by the release. Organizations should validate the installed channel and build rather than relying solely on the date a device last checked in with an update service.

Product or update channelAugust 11, 2026 security build
Current ChannelVersion 2607, Build 20228.20190
Monthly Enterprise Channel, Version 2607Build 20228.20188
Monthly Enterprise Channel, Version 2606Build 20131.20206
Monthly Enterprise Channel, Version 2605Build 20026.20266
Semi-Annual Enterprise Channel (Monthly Enterprise builds)Version 2607, Build 20228.20186
Semi-Annual Enterprise ChannelVersion 2508, Build 19127.20730
Office 2024 RetailVersion 2607, Build 20228.20190
Office 2021 RetailVersion 2607, Build 20228.20190
Office LTSC 2024 Volume LicensedVersion 2408, Build 17932.20910
Office LTSC 2021 Volume LicensedVersion 2108, Build 14334.20848
Office 2019 Volume LicensedVersion 1808, Build 10417.20197

For Microsoft 365 Apps, the build number is the meaningful compliance check. A device can report that it has a recent Office version while remaining on an earlier build in the same feature version, particularly where update channels, staged deployments, update deadlines, or management profiles delay the security payload.

The distinction is especially relevant for Monthly Enterprise Channel estates. Microsoft lists three supported Monthly Enterprise build families receiving the August 11 security update: Version 2607 Build 20228.20188, Version 2606 Build 20131.20206, and Version 2605 Build 20026.20266. A fleet intentionally held on an older channel build should receive the appropriate patched revision; it does not need to jump to the newest feature release merely to address this CVE.

For environments using Microsoft Configuration Manager, Intune, Office Deployment Tool controls, or a third-party patch platform, administrators should verify that Office content has actually been downloaded and applied. Office Click-to-Run update compliance is commonly misstated when management reporting captures the policy assignment but not the post-install product build.


Microsoft’s “Office suite” label widens the inventory check​

CVE-2026-70314 appears beside a large group of Office-suite vulnerabilities in Microsoft’s August release notes. That tells administrators what it doesn’t appear to be: Microsoft did not classify it as an Excel-only, Word-only, or Outlook-only issue.

The practical consequence is that teams should query the Office product family across endpoints, including shared-device deployments, Remote Desktop Session Host farms, virtual desktop images, kiosks, and systems where only a subset of the Office apps is routinely launched. A machine that does not use Word for daily work may still contain the suite components covered by the update.

This classification also argues against treating the advisory as a Windows cumulative-update issue. Windows Update rings alone will not prove that the Office desktop applications have received their August security update. Windows 11 can be fully current while Microsoft 365 Apps or Office LTSC remains on an older Office build.

For personal and small-business installations using automatic Office updates, the patch may arrive without separate administrator action. Enterprises that suppress automatic updates, host Office update content internally, use frozen golden images, or pin users to an update channel need a deliberate deployment check. The vulnerability is fixed through the Office servicing mechanism, and the exact build numbers above are the defensible verification point.

Office 2019’s appearance is a warning for legacy estates​

Microsoft’s August release notes list Office 2019 Volume Licensed Version 1808 Build 10417.20197 among the releases receiving this month’s security content. That is notable because Office 2019 support ended on October 14, 2025.

Microsoft’s Office update documentation says it may issue one or more Office 2019 updates after end of support at its discretion. August’s inclusion shows that at least some security content is still being shipped to that branch. It does not restore Office 2019 to a normal supported lifecycle or establish that future Office vulnerabilities will receive an Office 2019 fix.

Administrators should not read this patch as a reason to defer migration plans. The safer interpretation is narrower: if Office 2019 remains deployed, install the August build now, document it as an exceptional post-support security release, and continue moving the estate to Microsoft 365 Apps or a currently supported perpetual Office version.

The same principle applies to Windows 10 devices running Microsoft 365 Apps. Microsoft says it will continue providing Microsoft 365 security updates on Windows 10 through October 10, 2028, despite Windows 10 having reached end of support on October 14, 2025. That means the Office patch may still install on such machines, but it does not fix the broader exposure created by an unsupported operating system.


What Microsoft has not said about exploitation​

The advisory’s information-disclosure designation establishes a confidentiality risk, but it does not establish how serious the exposure is in a particular environment. Information disclosure can range from limited unintended data access to a flaw that helps an attacker collect sensitive content or circumvent protections as part of a larger intrusion. Microsoft has not publicly narrowed that range for CVE-2026-70314.

Nor has Microsoft said that the vulnerability is publicly disclosed or exploited in the wild. The generic explanation of confidence and exploit-code maturity included with the advisory material should not be mistaken for an actual exploitation rating. No score, vector, affected-file format, workaround, or detection guidance was supplied in the published details reviewed here.

No independent technical analysis or public proof of concept had surfaced alongside Microsoft’s August 11 disclosure. That is normal for a newly issued Office advisory, but it leaves defenders with a simple conclusion: apply the patch based on the vendor’s remediation guidance, not on speculation about an attack technique.

Security operations teams should therefore avoid writing detection rules around guessed filenames, macro events, Outlook preview behavior, or a presumed Office child-process pattern. There is no public evidence tying any of those to CVE-2026-70314. The useful telemetry for now is update compliance: Office version, build, channel, installation success, and machines excluded from normal servicing.

Verify the build, then close the exception​

A productive remediation pass for CVE-2026-70314 should include three checks:

  • Confirm that Microsoft 365 Apps devices have reached the August 11 build assigned to their update channel, not merely Version 2607, 2606, or 2605.
  • Confirm that Office LTSC 2021, Office LTSC 2024, Office 2021 Retail, Office 2024 Retail, and Office 2019 Volume Licensed installations match Microsoft’s listed August build where those products remain in use.
  • Identify endpoints unable to update because of disconnected networks, expired licenses, frozen images, unsupported operating systems, or disabled Office update services, then place them in a documented remediation exception queue.

Microsoft’s public record gives defenders the patch target but not the attack narrative. For CVE-2026-70314, the concrete risk-management decision is to make the August 11 Office build the minimum acceptable version across the estate — and to treat every exception, particularly Office 2019, as a legacy problem that needs an owner and a deadline.