CVE-2026-40361

Published May 12, 2026

Last updated 5 days ago

Overview

Description
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Source
secure@microsoft.com
NVD status
Modified
Products
365_apps, office, office_long_term_servicing_channel, word

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
5.9
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-416

Social media

Hype score
Not currently trending
  1. CVE-2026-40361 | Microsoft Outlook and Word Remote Code Execution Vulnerability | R.A.H.S.I. Framework™ https://t.co/pnSMYqAixs https://t.co/sL8igJVBTv

    @rahsi_aaka

    5 Jun 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 📰 Newsletter RadioCSIRT, N°54 Au sommaire de la semaine du 9 au 15 mai 2026 : famille Dirty Frag (CVE-2026-43284 / 43500), YellowKey contre BitLocker, CVE-2026-40361 zero-click Outlook, AMD-SB-7052, Shai-Hulud, et bien plus. https://t.co/fSsRlrZgPs ⚡ On ne réfléchi

    @marcfredericgo

    16 May 2026

    92 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 💥 Outlook - Faille zéro clic Le Patch Tuesday de mai 2026 publié par Microsoft corrige une faille de type zero-click affectant Outlook (et Word) : CVE-2026-40361. Voici comment se protéger. - https://t.co/o0wmbHpHk5 #outlook #infosec #microsoft https://t.co/zxxc5y2324

    @ITConnect_fr

    16 May 2026

    1033 Impressions

    7 Retweets

    16 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  4. 「2025年5月に提供された「CVE-2026-40361」 の修正プログラム」#パソコンのツボ https://t.co/1hs94z6yM0

    @pcclick007

    15 May 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🔐 セキュリティトレンド (14:53 JST) ① 「Windows Server 2025」に問題、ブルースクリーンでメモリダンプが生成されない/2026年5月 ... https://t.co/pos7xkKGHw ② Outlook ゼロクリック脆弱性 CVE-2026-40361|メール閲覧だけ

    @kenebeii

    14 May 2026

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 【Microsoft CVE-2026-40361、OutlookゼロクリックRCEとして優先パッチ対象】 Microsoftの2026年5月月例更新で修正されたCVE-2026-40361は、Outlook/Word関連のCritical

    @01ra66it

    14 May 2026

    435 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. microsoft CVE-2026-40361: RCE. patch tuesday came early. assume mass scanning starts within 48h. #Microsoft #RCE #AIsecurity #CVE-2026-40361 https://t.co/0A8e5X9RX8

    @trerbbb

    13 May 2026

    101 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 18:33 UTC: CVE-2026-40361 disclosed. CVE-2026-40361 ( patched today, is a critical 0-click UAF/RCE bug in Microsoft Outlook that I d 0day Intel: CVE-2026-40361 (https://t.co/osGIhRwvVi), patched today, is a critical 0-click U

    @lyrie_ai

    13 May 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. 9 new OPEN, 16 new PRO (9 + 7) DOILoader, Outlook Classic Use After Free Remote Code Execution Attempt (CVE-2026-40361), Rclone (CVE-2026-41176, CVE-2026-41179), TA569, Win32/Lumma Stealer https://t.co/aOnlJCYCq8

    @ET_Labs

    12 May 2026

    219 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.