CVE-2026-64918
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.49%
- CWE
- CWE-522
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- Microsoft Microsoft 365 Apps for Enterprise
- Microsoft Microsoft Office 2016
- Microsoft Microsoft Office 2019
- Microsoft Microsoft Office LTSC 2021
- Microsoft Microsoft Office LTSC 2024
Weakness type
Related vulnerabilities
- CVE-2026-69805 — .NET Elevation of Privilege Vulnerability
- CVE-2026-81381 — GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
- CVE-2026-77909 — Azure CycleCloud Information Disclosure Vulnerability
- CVE-2026-82070 — Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86726 — AVideo through 29.0 Information Disclosure via restreamsActive.json.php
- CVE-2026-61516 — Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
- CVE-2026-76969 — Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)