Skip to content
CodeAuditAgent

CVE-2026-40367

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Weakness

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected products

  • microsoft 365_apps
  • microsoft office
  • microsoft office_long_term_servicing_channel
  • microsoft sharepoint_server
  • microsoft word

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.