CVE-2026-32190General(microsoft / 365_apps)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_apps systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-15); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channel

5 versions affected across 3 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-19: 104-1404-1504-19
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-141
Patch1
2026-04-152
General2
2026-04-191
Disclosure1
Full discourse4 posts
  • Patel Mahendra@Mahendrak29
    General

    https://whatsapp.com/channel/0029VbAre6eKQuJNLsryuQ0u/112 🔴 Zero-Day CVE-2026-32201 – SharePoint Spoofing CVE-2026-33825 – Publicly Disclosed 🔴 Critical: CVE-2026-33827 – Windows RCE CVE-2026-33826 – Active Directory RCE CVE-2026-32157 – RDP Client RCE CVE-2026-32190 – Microsoft Office RCE #cyber

    Post summary

    The message lists several CVEs with brief descriptors but lacks details about PoC, exploitation, or patches.

    00010239
    1 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-32190: Microsoft Office Remote Code Execution Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04cDZ_C0

    Post summary

    The headline announces a CVE-2026-32190 remote code execution flaw in Microsoft Office and points readers toward business implications and response guidance.

    0000037
    29 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32190 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. https://www.cve.org/CVERecord?id=CVE-2026-32190

    Post summary

    The text reports a use‑after‑free vulnerability (CVE‑2026‑32190) that permits local code execution, but provides no PoC, exploit, or mitigation details.

    00000101
    57.2K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-32190 | Microsoft 365 Apps for Enterprise | Remote Code Execution Description Use-after-free vulnerability in Microsoft Office allows unauth attacker to achieve local RCE by tricking a user into opening a malicious document that triggers memory corruption during processing. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Microsoft 365 Apps for Enterprise Affected Version: >= 16.0.1 and < https://aka.ms/OfficeSecurityReleases Sources Vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32190

    Post summary

    Microsoft Office Use‑After‑Free CVE-2026-32190 enables local RCE for unauthenticated users; a patch has been released.

    0000067
    8 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice2016-x64
Appmicrosoftoffice2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-

Explore more