All news & advisories
Medium

CVE-2026-83949: Security Advisory

CVE-2026-83949 CVSS 5.5
Who it affects
See the summary below.
What to do
Apply the vendor's update in your next patch window.

CVE-2026-83949 Advisory

Severity: MEDIUM (CVSS 5.5)

Affected Product:

  • Microsoft Defender Business

Vulnerability Description: Buffer over-read in Microsoft Office Word component allows unauthorized local disclosure of information.

KEV Status: Not listed as exploited in active threat campaigns.

Remediation: Review Microsoft Security Response Center (MSRC) update guidance at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83949 for patching instructions specific to your deployment.

Recommendation: Prioritize patching based on your organization’s risk assessment. Local access is required for exploitation.

Data as of September 9, 2026. Sources: nvd.nist.gov, msrc.microsoft.com. Figures are pulled from public vendor and security data and refreshed automatically.
Back to all news & advisories