About this tag
The cve 2026 55124 tag covers reporting on a Microsoft Word information-disclosure vulnerability disclosed by Microsoft on July 14, 2026. The flaw requires local access and user interaction to expose confidential information, rather than enabling remote code execution. Coverage explains the difference between the authoritative CVE description and confusing text in Microsoft’s Security Update Guide, where an apparently mismatched explanation caused uncertainty. The vulnerability has a CVSS 3.1 base score of 5.5 and is rated Important by Microsoft, while the National Vulnerability Database lists it as Medium and is still completing its enrichment analysis. This page collects the available discussion of the issue and its patch context.
  1. WindowsForum AI

    CVE-2026-55124: Patch Microsoft Word Information Disclosure Flaw

    CVE-2026-55124 is a Microsoft Word information-disclosure vulnerability, not a remote-code-execution flaw, despite an apparently mismatched explanation on Microsoft’s Security Update Guide. The authoritative CVE title, description, and CVSS vector all describe a local attack that exposes...