Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisory

Microsoft Patches Critical Office and Word Use-After-Free RCE Flaws

Updated 2d agoFirst seen May 25, 20268 sources

Microsoft disclosed and fixed two critical use-after-free vulnerabilities affecting Microsoft Office and Microsoft Word: CVE-2026-40358 and CVE-2026-40366. Both bugs are classified as CWE-416 and carry a CVSS 8.4 rating, with Microsoft assessing impacts to confidentiality, integrity, and availability as high. The company said neither flaw had been publicly disclosed or exploited in the wild at the time of publication, and it rated exploitation as less likely.

Microsoft said the vulnerabilities can lead to remote code execution, although the attack vector is described as local, with the Preview Pane able to serve as an attack path when malicious content is handled. The disclosures continue a broader pattern of Microsoft patching multiple remote code execution issues across its product line, including earlier Office flaws such as CVE-2024-30101, CVE-2025-24080, and CVE-2025-59234, as well as RCE bugs in Windows Connected Devices Platform Service, Remote Desktop Protocol, and Inbox COM Objects.

Share:
Microsoft Patches Critical Office and Word Use-After-Free RCE Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
May 12, 20261mo ago

Microsoft discloses and patches CVE-2026-40366 in Microsoft Word

Microsoft disclosed CVE-2026-40366, a critical Microsoft Word use-after-free remote code execution vulnerability with a CVSS 8.4 score. Microsoft said the flaw was not publicly disclosed or exploited at publication, assessed exploitation as less likely, noted the Preview Pane as an attack vector, and made a fix available.

Microsoft discloses and patches CVE-2026-40358 in Microsoft Office

Microsoft disclosed CVE-2026-40358, a critical Microsoft Office use-after-free vulnerability that can lead to remote code execution, with a CVSS 8.4 score. Microsoft said exploitation was less likely, there was no public disclosure or in-the-wild exploitation at publication, the Preview Pane could be an attack vector, and a fix was available.

Oct 14, 20258mo ago

Microsoft discloses CVE-2025-59234 for Microsoft Office

Microsoft published a Security Update Guide entry for CVE-2025-59234, a Microsoft Office remote code execution vulnerability. The disclosure was included in Microsoft's October 2025 security updates.

Microsoft discloses CVE-2025-58737 in Remote Desktop Protocol

Microsoft published a Security Update Guide entry for CVE-2025-58737, a Remote Desktop Protocol remote code execution vulnerability. The advisory was released on October 14, 2025.

Microsoft discloses CVE-2025-58736 affecting Inbox COM Objects

Microsoft published a Security Update Guide entry for CVE-2025-58736, a remote code execution vulnerability in Inbox COM Objects (Global Memory). The disclosure was issued as part of the October 2025 security updates.

Jul 8, 20251y ago

Microsoft discloses CVE-2025-49724 in Windows Connected Devices Platform Service

Microsoft published a Security Update Guide entry for CVE-2025-49724, a remote code execution vulnerability in the Windows Connected Devices Platform Service. The advisory was released on July 8, 2025.

Mar 11, 20251y ago

Microsoft discloses CVE-2025-24080 for Microsoft Office

Microsoft published a Security Update Guide entry for CVE-2025-24080, a Microsoft Office remote code execution vulnerability. The disclosure occurred with Microsoft's March 2025 security updates.

Jun 11, 20242y ago

Microsoft discloses CVE-2024-30101 for Microsoft Office

Microsoft published a Security Update Guide entry for CVE-2024-30101, a Microsoft Office remote code execution vulnerability. The advisory indicates the vulnerability was disclosed as part of Microsoft's June 2024 security updates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Affected products
2 linked
Microsoft OfficeMicrosoft Office Word
Organizations
1 linked
Microsoft Corporation
SOURCE COVERAGE

Sources

8 references tracked. Mallory keeps watching after this page renders.

8 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Patches Critical Office and Word Use-After-Free RCE Flaws | Mallory