CVE-2026-55124: Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55124
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-551240.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55124 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] Microsoft Office products: Multiple vulnerabilitiescert-bund
- unknownexploitedNCSC-2026-0237 [1.02] [H/H] Vulnerabilities Fixed in Microsoft Officencsc-nl
- unknownexploitedNCSC-2026-0237 [1.01] [H/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- unknownMultiple vulnerabilities in Microsoft Office (July 15, 2026)cert-fr-avis
- unknownexploitedNCSC-2026-0237 [1.00] [M/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- mediumCVE-2026-55124: Microsoft Word Information Disclosure Vulnerabilitymsrc
Recent advisories for Improper validation of
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-67294: FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer ce…nvd · 2026-08-01
- mediumCVE-2026-67293: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname …nvd · 2026-08-01
- mediumCVE-2025-62347: HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unex…nvd · 2026-07-31
- mediumCVE-2026-66720: The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated…nvd · 2026-07-30
- criticalCVE-2026-13435: IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in t…nvd · 2026-07-30
- highCVE-2026-22622: Improper input validation in one of the session management interface of Eaton's Tripp Lite ser…nvd · 2026-07-30
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01