CVE-2026-77901
massNull Pointer Dereference RCE in Microsoft Word (Office 2019–2024, Microsoft 365)
CVE-2026-77901 is a NULL pointer dereference (CWE-476) in the Microsoft Word component of Office that Microsoft classifies as a flaw allowing an unauthenticated attacker to execute code over a network, with a CVSS 3.1 base score of 8.8. The attack path is network-delivered but requires user interaction (AV:N/PR:N/UI:R), meaning an attacker typically needs to get a user to open a maliciously crafted document that causes Word to dereference a null pointer. Successful exploitation would give the attacker code execution on the victim's machine in the user's context, with high impact to confidentiality, integrity and availability (C:H/I:H/A:H). Anyone running Word within Office 2019, Office 2021, Office 2024, Microsoft 365 or Microsoft 365 Apps is in scope. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and EPSS estimates only about a 0.6% probability of exploitation within 30 days, so no active exploitation is currently known.
What to do: Inventory your estate for Word within Office 2019, 2021, 2024, Microsoft 365 and Microsoft 365 Apps, and apply Microsoft's Word/Office security update for CVE-2026-77901 as soon as it is available (fixed build numbers are not listed in the available data; Microsoft 365 Apps normally receives fixes via its regular update channel). Until patching, keep Office Protected View enabled and treat unsolicited or untrusted Word documents with suspicion, since user interaction with a crafted document is the likely trigger. No workarounds are confirmed in the available data, so verify any mitigation guidance against Microsoft's advisory.
| Microsoft Word | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
| Microsoft 365 | — |
| Microsoft 365 Apps | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.