CVE-2026-45461CriticalRevised 19 Jun
Microsoft Office Remote Code Execution Vulnerability
Assessment
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- Severity
- Critical
- CVSS base score
- 8.4CVSS:3.1/
AV:L/ AC:L/ PR:N/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Remote Code Execution
- EPSS, next 30 days
- 0.4%Higher than 27.7% of scored CVEs · FIRST model run 29 Sep 2026 · about EPSS
- Public exploit code
- No Nuclei template lists it
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Office
- Weakness
- CWE-416: Use After Free
- Issued by
- Microsoft
- Published
- 9 Jun 2026 · June 2026
- Last revised
- 19 Jun 2026Microsoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.
Updates that fix it
1 KB| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5002878 | Security Update | — | Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition) | All CVEs in KB5002878 |
Affected products
Microsoft Office14 affected products
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Office 2016 (32-bit edition)
- Microsoft Office 2016 (64-bit edition)
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Microsoft Office 365 for Mac
- Microsoft Office for Android
- Microsoft Office LTSC 2021 for 32-bit editions
- Microsoft Office LTSC 2021 for 64-bit editions
- Microsoft Office LTSC 2024 for 32-bit editions
- Microsoft Office LTSC 2024 for 64-bit editions
- Microsoft Office LTSC for Mac 2021
- Microsoft Office LTSC for Mac 2024