CVE-2026-42831Patch(microsoft / 365_copilot)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft 365_copilot systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot
  • office
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-05-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
365_copilotofficeoffice_long_term_servicing_channel

2 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-18: 1Mentions · 2026-06-24: 1Active Exploitation · 2026-06-24: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-24: 105-1806-24
Signal classification2 categories
Patch
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-181
Patch1
2026-06-241
Active Exploitation1
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    The Office Kill-Chain Microsoft Office is the primary attack vector this month. Multiple CVEs allow attackers to chain email attachments → preview pane triggers → memory corruption → code execution, with no user action beyond opening an email: CVE-2026-42831 (Word RCE,…

    Post summary

    The post highlights that multiple Microsoft Office CVEs are currently being leveraged as primary attack vectors, causing memory corruption and code execution without user interaction; no PoC, patch, or exploit tool is discussed but active exploitation is implied.

    1000034
    295 followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    CVE-2026-42831: Critical Microsoft Office RCE Flaw Patched https://thecybrdef.com/cve-2026-42831-microsoft-office-rce-vulnerability/ #Cybertrending #Cybernewsdaily #Cybersecurity

    Post summary

    Microsoft Office RCE vulnerability CVE‑2026‑42831 is reported as patched in the headline.

    0000052
    9 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot-android-
Appmicrosoftoffice2024macos-
Appmicrosoftoffice_long_term_servicing_channel2021macos-

Explore more