Microsoft Office confidentiality flaw patched
ANSSI advisory covers a Microsoft Office vulnerability that could let an attacker compromise data confidentiality; patches available.
ANSSI (CERT-FR) published an advisory regarding CVE-2026-70105, a vulnerability affecting multiple Microsoft Office products including Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021/2024, Office for Mac, and Word 2016. The flaw allows an attacker to compromise the confidentiality of data processed by the affected applications.
No indication of active exploitation is provided in the advisory. Microsoft has released a security bulletin with corresponding patches. Organizations running the affected Office versions should apply the vendor-supplied updates as referenced in the Microsoft Security Response Center (MSRC) documentation to remediate the issue.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1072
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free