PatchSiren cyber security CVE debrief
CVE-2026-64918 Microsoft CVE debrief
A spoofing vulnerability exists in Microsoft Office due to insufficiently protected credentials, allowing an unauthorized attacker to perform spoofing over a network. This vulnerability affects various versions of Microsoft Office and Microsoft 365 Apps for Enterprise. The vulnerability can lead to security breaches if not addressed, emphasizing the need for defenders to assess their exposure, especially in environments with external or untrusted network access. Defenders should prioritize verifying exposure in their Office and Microsoft 365 deployments, especially where external or untrusted network access is possible. This includes IT security teams, system administrators, and A
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Microsoft Office and Microsoft 365 deployments should assess their exposure, especially in environments with external or untrusted network access. This includes IT security teams, system administrators, and network security engineers.
Why it matters
This vulnerability allows an unauthorized attacker to perform spoofing over a network, potentially leading to security breaches in affected Microsoft Office and Microsoft 365 deployments.
- Verify exposure in Office and Microsoft 365 deployments.
- Apply security updates to prevent exploitation.
- Monitor network activity for suspicious spoofing attempts.
- Update incident response plans to address potential spoofing attacks.
Technical summary
The vulnerability exists due to insufficiently protected credentials in Microsoft Office, allowing an unauthorized attacker to perform spoofing over a network. Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024.
Defensive priority
Defenders should prioritize verifying exposure in their Office and Microsoft 365 deployments, especially where external or untrusted network access is possible.
Recommended defensive actions
- Verify Office and Microsoft 365 deployments for exposure, especially where external access is possible.
- Apply security updates from Microsoft as available.
- Monitor network activity for suspicious spoofing attempts.
- Review and update incident response plans to address potential spoofing attacks.
Evidence notes
The CVE Program and NVD provide official records of this vulnerability. Microsoft has released a security update guide for this issue. The vulnerability is confirmed to affect multiple versions of Microsoft Office and Microsoft 365 Apps for Enterprise. Defenders should verify their deployments for exposure, especially where external access is possible, and apply security updates as available. The official CVE record and NVD detail page provide further information on the vulnerability,
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64918 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64918
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64918 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64918
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Microsoft Office Spoofing Vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/64xxx/CVE-2026-64918.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64918
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.