CVE-2026-64918

Summary

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office 201616.0.0 < 16.0.5569.1003affected
MicrosoftMicrosoft Office 201919.0.0 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office LTSC 202116.0.1 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office LTSC 202416.0.0 < https://aka.ms/OfficeSecurityReleasesaffected

Weaknesses

  • CWE-522: CWE-522: Insufficiently Protected Credentials

References