All news & advisories
Medium

CVE-2026-72976: Security Advisory

CVE-2026-72976 CVSS 5
Who it affects
See the summary below.
What to do
Apply the vendor's update in your next patch window.

CVE-2026-72976: Out-of-Bounds Read in Microsoft Defender Business

Severity: MEDIUM (CVSS 5.0)

Affected Product:

  • Microsoft Defender Business

Vulnerability Description: Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.

KEV Status: Not currently exploited in the wild

Remediation:

Impact: Local information disclosure only; requires authorization to exploit.

Data as of September 9, 2026. Sources: nvd.nist.gov, msrc.microsoft.com. Figures are pulled from public vendor and security data and refreshed automatically.
Back to all news & advisories