CVE-2026-40366

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

high 8.4 CVSS 3.1
Published: May 12, 2026
Modified: Jun 1, 2026
Vendor: Microsoft
Product: 365 Apps
Versions: 2019,2021,2024,2016