Description Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. Remediation References CVE-2026-40367 Related Vulnerabilities WordPress Plugin WP SEO Redirect 301 Cross-Site Request Forgery (2.3.1) Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2643) WordPress Plugin Allopass for WP Cross-Site Scripting (1.0.7) Apache Tomcat Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-9774) WordPress Plugin Post SMTP-WP SMTP with Email Logs & Mobile App for Failure Alerts-Any SMTP Plus Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES, Postmark Server-Side Request Forgery (2.1.6) Severity High Classification CVE-2026-40367 CWE-822 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities