About this tag
The office security tag covers recent Microsoft Office security updates, vulnerabilities, and policy changes affecting enterprise environments. Topics include Mark of the Web (MOTW) being added to Outlook attachments saved via OneDrive, which can break VBA workflows; Microsoft Purview DLP policies now blocking Copilot from processing sensitivity-labeled files regardless of storage location; and multiple July 2026 Patch Tuesday fixes for Excel, PowerPoint, and other Office applications addressing remote code execution (CVE-2026-55949, CVE-2026-55947, CVE-2026-54131, CVE-2026-55043) and information disclosure flaws (CVE-2026-56195, CVE-2026-55898). Discussions clarify CVSS scoring nuances, such as local attack vectors for RCE vulnerabilities, and emphasize the need for prompt patching and workflow testing.
  1. ChatGPT

    OneDrive 26.002 Adds MOTW to Outlook Attachments: Test VBA Workflows

    OneDrive for Windows now adds Mark of the Web to Outlook attachments saved into synced folders, so IT administrators should test and redesign legitimate email-based workflows rather than disable the security signal globally. The immediate risk is operational: macro-enabled workbooks, templates...
  2. ChatGPT

    Purview DLP Blocks Microsoft 365 Copilot for Labeled Files Anywhere

    Microsoft Purview Data Loss Prevention policies that block Microsoft 365 Copilot from processing sensitivity-labeled Word, Excel, and PowerPoint files now apply regardless of where those files are stored, according to Microsoft 365 Roadmap ID 557255. The item is marked Launched, with general...
  3. ChatGPT

    CVE-2026-56195: Install July Office Builds to Fix Memory Leak

    Microsoft’s July 14 Office security releases address CVE-2026-56195, an out-of-bounds read flaw that can disclose information from memory after a user opens malicious content in an affected Office installation. The vulnerability carries a CVSS 3.1 score of 5.5, rated Medium, but it spans...
  4. ChatGPT

    CVE-2026-55949: Patch Excel RCE in July 2026 Office Updates

    CVE-2026-55949 is a high-severity Microsoft Excel vulnerability that can let an attacker run arbitrary code after a user opens or otherwise processes malicious content locally. Microsoft classifies the flaw as a remote code execution vulnerability, but its CVSS 3.1 vector uses AV:L, or Local...
  5. ChatGPT

    CVE-2026-55947: Patch Excel RCE in July 14, 2026 Updates

    CVE-2026-55947 is an Important-rated Microsoft Excel remote code execution vulnerability, but its CVSS vector begins with AV:L—a combination that appears contradictory until the two labels are separated. “Remote code execution” describes where the attacker may be relative to the victim, while...
  6. ChatGPT

    CVE-2026-55898: Update Excel with KB5002886 to Stop Data Exposure

    Microsoft has patched CVE-2026-55898, an information-disclosure vulnerability in Microsoft Excel that can expose data through an out-of-bounds memory read. The flaw affects supported Windows and macOS editions of Office, as well as Office Online Server, and requires a user to interact with...
  7. ChatGPT

    CVE-2026-54131 Excel RCE: Why Microsoft Rates It AV:L

    CVE-2026-54131 is a high-severity Microsoft Excel vulnerability that can let an attacker run arbitrary code after a user opens or processes malicious content locally. Although Microsoft calls it a remote code execution vulnerability, its CVSS 3.1 vector begins with AV:L because exploitation...
  8. ChatGPT

    CVE-2026-55043: Patch PowerPoint Heap Overflow RCE

    CVE-2026-55043 is a Microsoft PowerPoint code-execution vulnerability that requires the vulnerable application to process malicious content on the victim’s machine. Its CVSS 3.1 vector begins with AV:L, but Microsoft still calls it a Remote Code Execution vulnerability because remote describes...
  9. ChatGPT

    CVE-2026-55130: Install KB5002890 to Fix Word Code Execution

    Microsoft patched CVE-2026-55130, a heap-based buffer overflow in Microsoft Word that can let an unauthenticated attacker execute code after a user opens malicious content. The July 14, 2026 security release covers Microsoft 365 Apps for enterprise, Office 2019, Office LTSC 2021 and 2024, Word...
  10. ChatGPT

    CVE-2026-55128: Patch Word RCE With KB5002890 and July 14 Updates

    Microsoft patched CVE-2026-55128, a high-severity Microsoft Word remote code execution vulnerability, in its July 14, 2026 security release. The use-after-free flaw can let an attacker run code after convincing a user to interact with malicious content, making prompt deployment important...
  11. ChatGPT

    CVE-2026-55142: Patch Microsoft Word Data Disclosure Flaw

    Microsoft has patched CVE-2026-55142, an Important-rated information disclosure vulnerability in Microsoft Word that can expose sensitive data when a user interacts with malicious content. The flaw affects Microsoft 365 Apps, supported perpetual Office releases, Word 2016, Office for Mac, and...
  12. ChatGPT

    CVE-2026-55134: Patch Microsoft Word RCE in July 2026 Updates

    CVE-2026-55134 is a Microsoft Word code-execution flaw rated 7.8 High, but its CVSS vector begins with AV:L rather than AV:N. That is not a contradiction: “remote code execution” describes the attacker’s resulting capability, while “local attack vector” describes where the vulnerable Word code...
  13. ChatGPT

    CVE-2026-55131: Patch Excel RCE With July 14 Office Updates

    CVE-2026-55131 is a high-severity Microsoft Excel vulnerability that can let an attacker run arbitrary code when a user interacts with malicious content, even though its CVSS vector classifies the attack as local. The apparent contradiction comes from two different uses of “remote”: remote code...
  14. ChatGPT

    CVE-2026-55122: Patch Excel Memory Disclosure in July Updates

    Microsoft has patched CVE-2026-55122, a high-severity information-disclosure vulnerability in Microsoft Excel that could expose sensitive process memory when a user interacts with a malicious file. The flaw affects Microsoft 365 Apps for Enterprise, Excel 2016, Office 2019, Office LTSC 2021 and...
  15. ChatGPT

    CVE-2026-55053: Patch Excel RCE With July 14 Updates

    CVE-2026-55053 exposes Microsoft Excel to remote code execution through a heap-based buffer overflow, allowing malicious workbook content to run code with the victim’s permissions. Microsoft released the fix on July 14, 2026, as part of its monthly security updates and rates the vulnerability...
  16. ChatGPT

    CVE-2026-55132: Patch Word RCE With July 14, 2026 Updates

    CVE-2026-55132 can let an attacker run code through Microsoft Word, but its CVSS attack vector is Local because the vulnerable document must be processed on the target system. Microsoft’s Remote Code Execution title describes the attacker’s relationship to the victim, not a network service that...
  17. ChatGPT

    CVE-2026-55038 Word RCE Fixed in July 14 Office Updates

    Microsoft has patched CVE-2026-55038, a Microsoft Word remote code execution vulnerability caused by a stack-based buffer overflow. The flaw carries a CVSS 3.1 score of 7.8 and an Important severity rating, making the July 14, 2026 Office updates the direct fix for affected Windows and Mac...
  18. ChatGPT

    CVE-2026-55055: Install July Word and SharePoint RCE Fix

    CVE-2026-55055 is a high-severity Microsoft Word code-execution vulnerability, but its CVSS attack vector is Local rather than Network. The apparent contradiction comes from two different uses of remote: Microsoft’s title describes the attacker’s position, while CVSS describes where the...
  19. ChatGPT

    CVE-2026-55044: Patch Excel RCE With KB5002886

    Microsoft has patched CVE-2026-55044, a high-severity Microsoft Excel remote code execution vulnerability that can let a malicious workbook run code under the victim’s account. The flaw carries a CVSS 3.1 score of 7.8 and affects Microsoft 365 Apps for enterprise, Excel 2016, Office 2019, Office...
  20. ChatGPT

    CVE-2026-55036: Patch Excel RCE in July 14 Office Updates

    CVE-2026-55036 is a newly patched Microsoft Excel remote code execution vulnerability that can let an attacker run code after a user opens malicious content. Microsoft released fixes on July 14, 2026, covering Microsoft 365 Apps, Office 2019, Office LTSC 2021 and 2024, Excel 2016, Office for...