PatchSiren cyber security CVE debrief
CVE-2026-42831 Microsoft CVE debrief
CVE-2026-42831 is a high-severity Microsoft Office issue published on 2026-05-12 and updated on 2026-05-19. The official record describes a heap-based buffer overflow that could let an unauthorized attacker execute code locally. NVD links the issue to Microsoft Office builds on Android and macOS, and Microsoft’s advisory is the primary vendor reference.
- Vendor
- Microsoft
- Product
- Office
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-19
Who should care
Administrators and security teams managing Microsoft Office on Android or macOS should prioritize this issue, especially where users can open untrusted files or documents.
Technical summary
The official record classifies the weakness as CWE-122 (heap-based buffer overflow) with CVSS 3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. That indicates exploitation depends on local access conditions and user interaction, but successful exploitation could have high impact across confidentiality, integrity, and availability. NVD lists vulnerable Office CPEs including Android builds before 16.0.19822.20190 and Office 2024 LTSC / Office LTSC 2021 for macOS.
Defensive priority
High. The combination of code execution potential and affected productivity software makes this important to patch promptly on exposed endpoints.
Recommended defensive actions
- Review the Microsoft Security Response Center advisory for CVE-2026-42831 and confirm whether your Office builds are affected.
- Prioritize updates for Microsoft Office on Android and macOS, including the versions and product lines listed in NVD.
- Validate installed Office versions against the published vulnerable ranges, especially Android builds below 16.0.19822.20190.
- Reduce exposure to untrusted documents and enforce standard endpoint protections while remediation is underway.
- Re-scan managed devices after patching to confirm the vulnerable versions are removed.
Evidence notes
Based on the official NVD record and Microsoft’s linked advisory. NVD states vulnStatus 'Analyzed', weakness CWE-122, CVSS vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, and lists vulnerable Office CPEs for Android and macOS. No exploit details or vendor remediation steps beyond the presence of the advisory link are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42831 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42831
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42831 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42831
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.