Microsoft has published a fix for CVE-2026-70317, a Microsoft Office information disclosure vulnerability, in the August 11, 2026 Office security release. The immediate operational task is straightforward: organizations running Microsoft 365 Apps, perpetual Office editions, or Office LTSC should move to Microsoft’s listed August builds rather than treating this as a Windows Update-only event.

Microsoft’s Security Update Guide identifies the flaw as affecting the Office suite, while the company’s Office security release notes place CVE-2026-70317 in the August 11 update set. The public disclosure confirms the vulnerability and the availability of a vendor fix, but it does not provide a technical description of the underlying bug, a public proof of concept, a named attack vector, or evidence of exploitation in the wild.

That lack of detail changes the response from incident-driven emergency patching to disciplined Office servicing: confirm the installed Office update channel, deploy the corresponding August release, and verify the client build afterward. The release is only a day old, and no independent security research or reporting located at publication time has filled in the missing exploitation mechanics.

IT administrator monitors Microsoft Office security updates, patch progress, and endpoint compliance across multiple screens.Microsoft groups CVE-2026-70317 under the Office suite​

Microsoft’s August release notes do not assign CVE-2026-70317 to Word, Excel, Outlook, PowerPoint, or Access individually. It appears in the Office suite category, alongside a large group of Office-wide fixes published on August 11.

That designation is important for administrators because it argues against narrowing remediation to users of one document format or one Office application. A vulnerability listed against the Office suite can involve shared components, document-handling libraries, common services, or functionality packaged across the desktop suite. Microsoft has not identified which component is responsible here, so there is no defensible basis for exempting a deployment simply because its users primarily work in Word or Excel rather than another Office app.

The public advisory labels the impact as information disclosure. In practical terms, Microsoft is acknowledging a condition that could expose information to an unauthorized party, but the company has not said what information could be disclosed, whether exploitation requires a malicious document, whether a victim must open content, whether Preview Pane handling is involved, or whether an attacker needs prior local or network access.

Those omissions are not unusual in a fresh Office advisory, but they matter. An “information disclosure” label alone does not establish that CVE-2026-70317 is a document-delivered phishing risk, a local access weakness, or a server-side exposure. Security teams should avoid inventing an attack chain from the CVE category. The record supports patching; it does not yet support claims about a particular delivery method or a specific data-theft scenario.

August builds cover subscription and perpetual Office releases​

Microsoft’s Office release notes list CVE-2026-70317 in the August 11 security update across the current Microsoft 365 Apps servicing releases and supported perpetual-product builds. The relevant target builds are:

  • Microsoft 365 Apps Current Channel is version 2607, build 20228.20190.
  • Monthly Enterprise Channel is version 2607, build 20228.20188, with prior Monthly Enterprise builds 20131.20206 and 20026.20266 also listed in the August release set.
  • Semi-Annual Enterprise Channel is version 2607, build 20228.20186, while the standard Semi-Annual Enterprise Channel remains on version 2508, build 19127.20730.
  • Office 2024 Retail and Office 2021 Retail are version 2607, build 20228.20190.
  • Office LTSC 2024 Volume Licensed is version 2408, build 17932.20910.
  • Office LTSC 2021 Volume Licensed is version 2108, build 14334.20848.
  • Office 2019 Volume Licensed is version 1808, build 10417.20197.

The inclusion of Office 2019 in the August build list deserves a careful reading. Microsoft’s release-note page says support for Office 2019 ended on October 14, 2025, while also reserving the right to issue updates after that date. In other words, Microsoft has supplied an August 2026 build for Office 2019 volume-license customers, but that should not be mistaken for restoration of normal product support or a durable security-update commitment.

For organizations that retained Office 2019 after its end-of-support date, this is a useful patch but a poor basis for postponing migration. The next newly discovered Office issue may not receive an equivalent exception. Asset inventories should flag Office 2019 separately from actively supported Office LTSC and Microsoft 365 Apps installations, even where the August update can be deployed.

The confirmed status is stronger than the public technical detail​

The language included with Microsoft’s CVSS reporting defines the advisory’s report-confidence metric, which indicates whether a vulnerability’s existence and known details are considered credible. Microsoft’s publication of CVE-2026-70317 through the Security Update Guide establishes that the vendor has acknowledged and remediated the issue.

But confirmation is not the same as public exploitability evidence. At publication, Microsoft has not publicly described an exploit, published a workaround, named a discoverer, or stated that attacks are occurring. The absence of a workaround is also meaningful: Microsoft’s documented remediation is the updated Office build, not a registry setting, Protected View adjustment, feature removal, or configuration change.

Administrators should distinguish that from the more urgent Office cases in which Microsoft explicitly reports active exploitation or issues defensive guidance before a broad patch is available. Nothing in the current CVE-2026-70317 record supports calling it a zero-day, associating it with a threat actor, or declaring that users are already being targeted.

The security value of prompt deployment remains real. Microsoft’s detailed public explanation is limited, and attackers frequently reverse-engineer security updates after release. A low-detail advisory does not mean the corrected code change is low-value intelligence. It means defenders should close the gap before external analysis makes the defect easier to reproduce.

Verify the Office client, not merely Windows patch compliance​

The common failure mode with Office CVEs is assuming that a fully patched Windows 11 device has also received the required Office fixes. That assumption is unsafe in mixed estates. Microsoft 365 Apps generally service through Click-to-Run and channel policy, while volume-licensed LTSC and older perpetual editions can follow different servicing and management paths.

For Microsoft 365 Apps, administrators should use the Microsoft 365 Apps admin center, Endpoint Configuration Manager, Intune update policy, or their established Click-to-Run deployment process to confirm that clients have reached the appropriate August 11 build for their channel. On individual systems, the version shown under an Office application’s Account page is useful for spot verification, but centralized inventory should be the authority for deployment reporting.

For Office LTSC and Office 2019 volume-license environments, validate that the organization’s update source — Windows Server Update Services, Configuration Manager, Microsoft Update, or another managed mechanism — has approved and installed the August Office update. Devices that are offline, excluded from Microsoft Update, pinned to an older update location, or blocked by application-control testing rings are the most likely to remain behind.

A practical deployment sequence is:

  • Identify every installed Office product family and servicing channel before approving the update broadly.
  • Pilot the August Office release on representative add-in-heavy and macro-dependent endpoints, particularly where finance, document management, or line-of-business Office integrations are involved.
  • Deploy the applicable build to the remaining fleet and check for clients that remain below the August 11 version after the normal update window.
  • Keep phishing and attachment-handling controls in place, but do not present them as a documented mitigation for CVE-2026-70317 because Microsoft has not made that claim.

The missing attack details make patch verification the real control​

CVE-2026-70317 is a routine but substantive Office security fix: Microsoft has confirmed an information disclosure vulnerability, published it on August 11, and included it in builds spanning Microsoft 365 Apps, Office 2024, Office 2021, Office LTSC, and an exceptional Office 2019 update. What Microsoft has not disclosed is enough to prevent a precise risk narrative beyond that.

The concrete consequence is that organizations cannot safely scope this vulnerability by file type, Office application, or presumed user behavior. Patch the Office suite to the applicable August 2026 build, verify the installed version centrally, and treat any Office 2019 device that receives this update as a migration priority rather than a newly supported asset.