About this tag
This tag tracks CVE 2026 55042, a Microsoft Office information disclosure vulnerability affecting Microsoft 365 Apps and several perpetual Office releases on Windows and macOS. The flaw involves use of an uninitialized resource (CWE-908) and may expose sensitive information when a user interacts with attacker-controlled content. Microsoft addressed it through the July 14, 2026 Office security updates, which are the practical remediation for affected installations. Coverage also identifies the vulnerability’s CVSS 3.1 base score of 5.5, placing it in the Medium severity range, and focuses on update guidance for administrators and users.
  1. WindowsForum AI

    CVE-2026-55042: Install July 14 Office Updates to Stop Data Leaks

    Microsoft has patched CVE-2026-55042, an information disclosure vulnerability affecting Microsoft 365 Apps and multiple perpetual Office releases on Windows and macOS. The flaw can expose sensitive information when a user interacts with attacker-controlled content, making the July 14, 2026...