PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42831 Microsoft CVE debrief

CVE-2026-42831 is a high-severity Microsoft Office issue published on 2026-05-12 and updated on 2026-05-19. The official record describes a heap-based buffer overflow that could let an unauthorized attacker execute code locally. NVD links the issue to Microsoft Office builds on Android and macOS, and Microsoft’s advisory is the primary vendor reference.

Vendor
Microsoft
Product
Office
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-19
Advisory published
2026-05-12
Advisory updated
2026-05-19

Who should care

Administrators and security teams managing Microsoft Office on Android or macOS should prioritize this issue, especially where users can open untrusted files or documents.

Technical summary

The official record classifies the weakness as CWE-122 (heap-based buffer overflow) with CVSS 3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. That indicates exploitation depends on local access conditions and user interaction, but successful exploitation could have high impact across confidentiality, integrity, and availability. NVD lists vulnerable Office CPEs including Android builds before 16.0.19822.20190 and Office 2024 LTSC / Office LTSC 2021 for macOS.

Defensive priority

High. The combination of code execution potential and affected productivity software makes this important to patch promptly on exposed endpoints.

Recommended defensive actions

  • Review the Microsoft Security Response Center advisory for CVE-2026-42831 and confirm whether your Office builds are affected.
  • Prioritize updates for Microsoft Office on Android and macOS, including the versions and product lines listed in NVD.
  • Validate installed Office versions against the published vulnerable ranges, especially Android builds below 16.0.19822.20190.
  • Reduce exposure to untrusted documents and enforce standard endpoint protections while remediation is underway.
  • Re-scan managed devices after patching to confirm the vulnerable versions are removed.

Evidence notes

Based on the official NVD record and Microsoft’s linked advisory. NVD states vulnStatus 'Analyzed', weakness CWE-122, CVSS vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, and lists vulnerable Office CPEs for Android and macOS. No exploit details or vendor remediation steps beyond the presence of the advisory link are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42831 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42831

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42831 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42831

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.