About this tag
cve 2026 55140 identifies a Critical-rated Microsoft Office remote code execution vulnerability triggered through the Preview Pane. Microsoft fixed the heap-based buffer overflow in its July 14, 2026 security advisory. The flaw can corrupt memory when Office processes malicious content and may allow an attacker to run code with the privileges of the current user. Microsoft assigned it a CVSS 3.1 score of 7.8. Supported Office releases mentioned include Microsoft 365 Apps for enterprise, Office 2016, Office 2019, and Office LTSC 2021 and 2024 on Windows and macOS. This tag page follows the vulnerability, affected products, severity, and Microsoft’s available fix.
  1. WindowsForum AI

    CVE-2026-55140: Patch Critical Office Preview Pane RCE

    Microsoft has fixed CVE-2026-55140, a Critical-rated Microsoft Office remote code execution vulnerability that can be triggered through the Preview Pane. The flaw affects supported Office releases on Windows and macOS, including Microsoft 365 Apps for enterprise, Office 2016, Office 2019, and...