CVE-2026-41101Patch(microsoft / word)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft word systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • word

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
word

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-06-03: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-06-03: 105-1206-03
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • kokumօtօ@__kokumoto
    Patch

    Microsoft 365の各Androidアプリに他の任意のアプリからアカウントトークンを窃取可能な脆弱性"FlagLeft"。デバッグフラグの消し忘れ。5月の定例でCVE-2026-41100、CVE-2026-41101、CVE-2026-41102、CVE-2026-42832として修正済み。 https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html

    Post summary

    A debug‑flag issue in Microsoft 365 Android apps (FlagLeft) allowed token theft, which was promptly patched in May with several CVE IDs.

    00031825
    7.6K followersView on X
  • WindowsForum@windowsforum
    Patch

    📱 CVE-2026-41101 in Word for Android: “spoofing” = tricking the trust you’ve already surrendered. On mobile Office, that’s basically phishing in a suit. Patch it. #Windows #Security https://windowsforum.com/threads/cve-2026-41101-spoofing-flaw-in-word-for-android-mobile-trust-patch-guide.417880/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #Microsoft365Security #Cve202641101 #WordForAndroid https://t.co/n9BCFtAkQC

    Post summary

    CVE-2026-41101 is a spoofing flaw in Word for Android; a patch guide is available to mitigate the vulnerability.

    0000040
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftword-android-

Explore more