CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability
Acknowledgement Updated
Acknowledgement Updated
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Updated an acknowledgement. This is an informational change only.
Updated an acknowledgement. This is an informational change only.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Corrected Build Number in the Security Updates table. This is an informational change only.
Updated an acknowledgement. This is an informational change only.
Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only.
Updated an acknowledgement. This is an informational change only.
Updated an acknowledgement. This is an informational change only.
Updated an acknowledgement. This is an informational change only.
Updated an acknowledgement. This is an informational change only.
Information published.
Information published.
Information published.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Corrected the CVE description and title. This is an informational change only.
Information published.
Information published.
Information published.
Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network.