CVE-2026-20952Active Exploitation(microsoft / 365_apps)

MEDIUMCVSS 8.4 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channel

5 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-09: 2Active Exploitation · 2026-02-09: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 102-09
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-43300 2 - CVE-2026-20952 3 - CVE-2026-25253 4 - CVE-2025-26399 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without providing any technical details or actionable information.

    00010218
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Uninstalling KB5074109 removes patches for 114 vulnerabilities, including 3 zero-days actively exploited (e.g., CVE-2026-20952 for Office remote code execution, and flaws in Desktop Window Manager allowing privilege escalation). This exposes your system to risks like malware infection, data theft, or unauthorized access. Consider pausing updates temporarily or awaiting Microsoft's fix for the FPS issues instead.

    Post summary

    Uninstalling KB5074109 removes patches for 114 vulnerabilities, including three zero‑day flaws that are actively exploited, notably CVE‑2026‑20952 in Office. Users are warned to pause updates or await Microsoft’s fix to mitigate the heightened risk.

    000101.3K
    8.1M followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice2016-x64
Appmicrosoftoffice2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-

Explore more