CVE-2026-80080
massDouble Free RCE in Microsoft Word
Microsoft Word contains a double free memory-corruption flaw (CWE-415) that Microsoft assigned an 8.8 High CVSS score, in which an unauthorized attacker can execute code over a network with no privileges required but user interaction needed. Consistent with the user-interaction requirement in the CVSS vector, exploitation almost certainly requires a user to open a specially crafted document delivered by the attacker. Successful exploitation yields arbitrary code execution in the context of the current user, with high confidentiality, integrity, and availability impact. All users of Microsoft Word shipped in Microsoft 365 Apps, Microsoft 365, and Office 2019, 2021, and 2024 are affected. As of the latest data there is no known in-the-wild exploitation, no public proof of concept, and EPSS estimates only a 0.6% probability of exploitation within 30 days (percentile 47).
What to do: Apply the Microsoft security update addressing CVE-2026-80080 through the Microsoft Update and Office update channels on all systems running Word in Microsoft 365 Apps, Microsoft 365, or Office 2019/2021/2024, and consult Microsoft's advisory for exact affected and fixed build numbers. Until patched, rely on user-interaction-dependent mitigations such as Protected View, warn-before-open policies, and caution with unsolicited documents, since exploitation requires opening attacker-supplied content. Prioritize patching workstations that routinely open external documents and monitor Microsoft and CISA channels for updated exploitation signals.
| Microsoft Word | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.