PatchSiren cyber security CVE debrief
CVE-2026-35440 Microsoft CVE debrief
CVE-2026-35440 is a medium-severity information disclosure vulnerability in Microsoft Office Word, published on 2026-05-12 and last modified on 2026-05-19. The vulnerability stems from files or directories being accessible to external parties, allowing an unauthorized attacker to disclose information locally. The CVSS 3.1 score of 5.5 reflects local attack vector, low attack complexity, no privileges required, but user interaction required, with high impact to confidentiality and no impact to integrity or availability. Microsoft has assigned CWE-552 (Files or Directories Accessible to External Parties) as the primary weakness. The vulnerability affects multiple Microsoft Office product lines including Microsoft 365 Apps for Enterprise (x64 and x86), Office 2019 (x64 and x86), Office Long Term Servicing Channel 2021 and 2024 (x64 and x86), and Word 2016 (x64 and x86). As this is a local information disclosure issue requiring user interaction, exploitation would likely involve social engineering to convince a user to open a malicious document or interact with a compromised file in a way that exposes sensitive local information. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Organizations should apply security updates from Microsoft as they become available and follow Microsoft's guidance for the affected products.
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-19
Who should care
Organizations running affected Microsoft Office versions, security teams managing endpoint protection, and users handling sensitive documents in enterprise environments.
Technical summary
Local information disclosure vulnerability in Microsoft Office Word caused by files or directories accessible to external parties (CWE-552). Requires user interaction but no privileges. Affects Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, and Word 2016 across x64 and x86 architectures.
Defensive priority
medium
Recommended defensive actions
- Apply security updates from Microsoft for affected Office products as they become available
- Review and implement Microsoft's security guidance for Office document handling
- Educate users on safe document handling practices to reduce risk of social engineering
- Monitor for unusual file access patterns in Office applications
- Consider implementing application control policies to restrict untrusted Office documents
Evidence notes
CVE published 2026-05-12, modified 2026-05-19. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. CWE-552 assigned by Microsoft. Affected products confirmed via NVD CPE criteria. Not present in CISA KEV.
Official resources
-
CVE-2026-35440 CVE record
CVE.org
-
CVE-2026-35440 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
2026-05-12