High severity7.7NVD Advisory· Published May 12, 2026· Updated May 16, 2026
CVE-2026-42832
CVE-2026-42832
Description
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42832nvdVendor Advisory
News mentions
50- AI Doctors? Lawsuits Say No, Some Doctors Say YesGovInfoSecurity · May 18, 2026
- SecurityScorecard Buys Driftnet for More Internet VisibilityGovInfoSecurity · May 18, 2026
- Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security · May 17, 2026
- Colorado governor commutes prison sentence for election denier Tina PetersCyberScoop · May 15, 2026
- American Lending Center Data Breach Affects 123,000 IndividualsSecurityWeek · May 15, 2026
- Bypassing On-Camera Age-Verification ChecksSchneier on Security · May 15, 2026
- White House cyber official: identity security matters more than ever in the age of AICyberScoop · May 14, 2026
- ODNI taps officials to coordinate response to foreign election threatsThe Record · May 14, 2026
- ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News · May 14, 2026
- Deepfake sextortion forces schools to remove student photos from websitesMalwarebytes Labs · May 14, 2026
- ICO Publishes Five-Step Plan to Counter Emerging AI-Powered AttacksInfosecurity Magazine · May 14, 2026
- CERN’s open source KiCad library gives the world 17,000 circuit board componentsHelp Net Security · May 14, 2026
- Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risksCyberScoop · May 13, 2026
- DOJ releases legal rationale for nationwide voter data collectionCyberScoop · May 13, 2026
- Weaponized AI: The new frontier of fraud and identity spoofingCyberScoop · May 13, 2026
- Microsoft fixes Windows Autopatch bug installing restricted driversBleepingComputer · May 13, 2026
- Texas sued Netflix over claims it secretly collected and sold users’ dataMalwarebytes Labs · May 13, 2026
- 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous ValidationBleepingComputer · May 13, 2026
- Microsoft says some users can't install Office on Windows 365 devicesBleepingComputer · May 13, 2026
- May 2026 Patch Tuesday: no zero-days but plenty to fixMalwarebytes Labs · May 13, 2026
- Global Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain RisksInfosecurity Magazine · May 13, 2026
- Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE FlawsThe Hacker News · May 13, 2026
- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026
- It's Patch Tuesday for Microsoft & Not a Zero-Day In SightDark Reading · May 12, 2026
- UK fines water supplier $1.3M for exposing data of 664k customersBleepingComputer · May 12, 2026
- Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Intelligence · May 12, 2026
- Microsoft May 2026 Patch Tuesday, (Tue, May 12th)SANS Internet Storm Center · May 12, 2026
- Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-daysBleepingComputer · May 12, 2026
- Microsoft Patches 137 VulnerabilitiesSecurityWeek · May 12, 2026
- Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)Tenable Blog · May 12, 2026
- Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 MalwareSecurityWeek · May 12, 2026
- 20 Leaders Who Built the CISO Era: 2 Decades of ChangeDark Reading · May 12, 2026
- South Staffordshire Water Fined £1m After Data BreachInfosecurity Magazine · May 12, 2026
- Japan’s PM orders cybersecurity review to stop Mythos going full CyberZillaThe Register Security · May 12, 2026
- FCC Softens Ban on Foreign-Made RoutersDark Reading · May 11, 2026
- FCC pushes ban on security updates for foreign-made routers, drones to 2029The Record · May 11, 2026
- Poor security left hackers inside water company network for nearly two yearsHelp Net Security · May 11, 2026
- UK water company allowed hackers to lurk undetected for nearly two years, regulator findsThe Record · May 11, 2026
- Police take down relaunched criminal marketplace with 22,000 users, €3.6 million in revenueHelp Net Security · May 11, 2026
- US: FCC Relaxes Foreign-Made Router Ban to Allow for Security UpdatesInfosecurity Magazine · May 11, 2026
- Police Shut Relaunched Crimenetwork Dark Web MarketplaceInfosecurity Magazine · May 11, 2026
- Police shut down reboot of Crimenetwork marketplace, arrest adminBleepingComputer · May 10, 2026
- Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security · May 10, 2026
- Friday Squid Blogging: Giant Squid Live in the Waters of Western AustraliaSchneier on Security · May 8, 2026
- ‘PCPJack’ Worm Removes TeamPCP Infections, Steals CredentialsSecurityWeek · May 8, 2026
- Has CISA Finally Found Its New Leader in Tom Parker?Dark Reading · May 7, 2026
- Unplug your way to better codeCisco Talos Intelligence · May 7, 2026
- Why Security in 2026 Requires Continuous Threat and Exposure Management (CTEM) at ScaleRapid7 Blog · May 7, 2026
- Exploits and vulnerabilities in Q1 2026Securelist · May 7, 2026
- From Stuxnet to ChatGPT: 20 News Events That Shaped CyberDark Reading · May 6, 2026