
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20953 is a use-after-free vulnerability in Microsoft Office that allows an unauthorized local attacker to execute arbitrary code. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Office 2016, 2019, 2021, 2024 (including LTSC variants for Windows x86/x64 and macOS), and Microsoft 365 Apps for Enterprise. The vulnerability carries a CVSS v3.1 base score of 8.4 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The root cause is a use-after-free memory corruption flaw (CWE-416) within Microsoft Office's processing logic. According to the Feedly executive summary, the vulnerability can be triggered through the Preview Pane without requiring user interaction, enabling zero-click exploitation via specially crafted emails. The attack vector is local (AV:L) with no privileges required and no user interaction needed, suggesting the Preview Pane rendering context satisfies the local execution requirement. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation results in complete compromise of the affected system, with high impact to confidentiality, integrity, and availability. An attacker who exploits this vulnerability can execute arbitrary code in the context of the Office application, potentially enabling data theft, installation of malware, or lateral movement within an enterprise environment. The zero-click exploitation capability via the Preview Pane is particularly dangerous in enterprise settings where Microsoft Office is widely deployed, as it allows silent compromise without any user awareness or interaction (Feedly).
Microsoft released security updates on January 13, 2026, addressing this vulnerability across all affected products. Specific fixed versions include Microsoft Office 2016 updated to build 16.0.5535.1000 or later, and macOS variants of Office LTSC 2021 and 2024 updated to version 16.105.26011018 or later. For Office 2019, 2021, 2024, and Microsoft 365 Apps for Enterprise, updates are available via https://aka.ms/OfficeSecurityReleases. As a temporary workaround while patching, administrators should consider disabling the Preview Pane in Outlook to reduce the zero-click attack surface (Microsoft MSRC, Feedly).
The January 2026 Patch Tuesday release, which included CVE-2026-20953 among 113–114 total CVEs, received broad coverage from security vendors and researchers. Tenable, Qualys, CrowdStrike, Sophos, Zero Day Initiative, and Arctic Wolf all published Patch Tuesday analysis posts covering this release (Tenable Blog, ZDI Blog, Qualys Blog). The Stack Technology specifically highlighted Office as being "at high risk" in its Patch Tuesday coverage. Social media discussion on Mastodon and Bluesky noted the zero-click Preview Pane exploitation angle as a particularly concerning aspect of this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."