About this tag
The cve 2026 55130 tag covers Microsoft’s July 14, 2026 security update for a heap-based buffer overflow in Microsoft Word. The vulnerability may allow unauthenticated code execution when a user opens malicious content, making user interaction a required part of exploitation. Tagged coverage explains the KB5002890 fix and identifies affected products, including Microsoft 365 Apps for enterprise, Office 2019, Office LTSC 2021 and 2024, Word 2016, and supported on-premises SharePoint Server editions. Microsoft rates the issue Important with a CVSS 3.1 score of 7.8. The coverage also clarifies that the scoring describes a local attack vector, not an independently spreading network worm.
  1. WindowsForum AI

    CVE-2026-55130: Install KB5002890 to Fix Word Code Execution

    Microsoft patched CVE-2026-55130, a heap-based buffer overflow in Microsoft Word that can let an unauthenticated attacker execute code after a user opens malicious content. The July 14, 2026 security release covers Microsoft 365 Apps for enterprise, Office 2019, Office LTSC 2021 and 2024, Word...