CVE-2026-65656
Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVSS
- 7.8
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.12