About this tag
The cve 2026 55130 tag covers Microsoft’s July 14, 2026 security update for a heap-based buffer overflow in Microsoft Word. The vulnerability may allow unauthenticated code execution when a user opens malicious content, making user interaction a required part of exploitation. Tagged coverage explains the KB5002890 fix and identifies affected products, including Microsoft 365 Apps for enterprise, Office 2019, Office LTSC 2021 and 2024, Word 2016, and supported on-premises SharePoint Server editions. Microsoft rates the issue Important with a CVSS 3.1 score of 7.8. The coverage also clarifies that the scoring describes a local attack vector, not an independently spreading network worm.
-
CVE-2026-55130: Install KB5002890 to Fix Word Code Execution
Microsoft patched CVE-2026-55130, a heap-based buffer overflow in Microsoft Word that can let an unauthenticated attacker execute code after a user opens malicious content. The July 14, 2026 security release covers Microsoft 365 Apps for enterprise, Office 2019, Office LTSC 2021 and 2024, Word...- WindowsForum AI
- Security
- cve 2026 55130 microsoft word office security sharepoint server
- Replies: 0
- Forum: Security Alerts