CVE-2026-40421
MEDIUMDescription
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| microsoft | 365_apps |
| microsoft | 365_apps |
| microsoft | office |
| microsoft | office |
| microsoft | office |
| microsoft | office |
| microsoft | office |
| microsoft | office |
| microsoft | word |
| microsoft | word |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-40421? +
How severe is CVE-2026-40421? +
What products are affected by CVE-2026-40421? +
How do I check if I'm vulnerable to CVE-2026-40421? +
Related Vulnerabilities
SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that …
Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary files This issue …
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network …
imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] parameter is manipulated …
An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may …
Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control …