CVE-2026-72972 Advisory
Severity: HIGH (CVSS 8.8)
Affected Product:
- Microsoft Defender Business
Vulnerability Description: Heap-based buffer overflow in Microsoft Office Word allows remote code execution over a network.
KEV Status: Not currently listed as exploited in the wild.
Remediation: Apply security updates from Microsoft. Refer to the official vulnerability guidance at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72972
Recommendation: Prioritize patching due to HIGH severity rating and remote exploitation potential.