Microsoft Office Use-After-Free Remote Code Execution Vulnerability
CVE-2026-20953 is a use-after-free vulnerability in Microsoft Office. The provided content consistently describes it as a memory-safety flaw in Office that can lead to code execution when Office processes a specially crafted document or related preview content. Multiple sources in the content characterize it as a Critical Microsoft Office remote code execution vulnerability with CVSS 8.4, and specifically note that the Preview Pane is a valid attack vector. Affected products listed in the content include Microsoft Office LTSC for Mac 2021 and 2024, Office LTSC 2024, Office LTSC 2021, Office 2019, Office 2016, and Microsoft 365 Apps for Enterprise. Although one terse description says it allows an unauthorized attacker to execute code locally, the supporting context indicates practical exploitation can occur through attacker-supplied Office content delivered to a target, including malicious documents and, in some scenarios, preview handling.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical Microsoft Office remote code execution via maliciously crafted Office files; includes an Outlook preview-pane exploitation vector per the content.
A Microsoft Office use-after-free enabling local arbitrary code execution, with some attack paths requiring little/no user interaction (including Preview Pane rendering).
A Microsoft Office use-after-free enabling local arbitrary code execution, with some attack paths requiring little/no user interaction (including Preview Pane rendering).
A critical remote code execution vulnerability in Microsoft Office triggered via a malicious Office document (potentially exploitable via Outlook Preview Pane per the content).
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.