Microsoft Office
127 known vulnerabilities in Microsoft Office, 3 critical, 18 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-21514 CVSS 7.8 high · actively exploited Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
- CVE-2026-21509 CVSS 7.8 high · actively exploited Microsoft Office Security Feature Bypass Vulnerability
- CVE-2024-38226 CVSS 7.3 high · actively exploited Microsoft Publisher Protection Mechanism Failure Vulnerability
- CVE-2024-38189 CVSS 8.8 high · actively exploited Microsoft Project Remote Code Execution Vulnerability
- CVE-2024-21413 CVSS 9.8 critical · actively exploited Microsoft Outlook Improper Input Validation Vulnerability
- CVE-2023-36761 CVSS 6.5 medium · actively exploited Microsoft Word Information Disclosure Vulnerability
- CVE-2023-35311 CVSS 8.8 high · actively exploited Microsoft Outlook Security Feature Bypass Vulnerability
- CVE-2023-23397 CVSS 9.8 critical · actively exploited Microsoft Office Outlook Privilege Escalation Vulnerability
- CVE-2021-42292 CVSS 7.8 high · actively exploited Microsoft Excel Security Feature Bypass
- CVE-2021-38646 CVSS 7.8 high · actively exploited Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Latest vulnerabilities
- CVE-2026-100208 CVSS 7.5 high Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2026-70125 CVSS 8.8 high Microsoft Office Outlook Remote Code Execution Vulnerability
- CVE-2026-85875 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-83951 CVSS 5.5 medium Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-83949 CVSS 5.5 medium Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-81960 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81959 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81958 CVSS 5.5 medium Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81957 CVSS 7.8 high Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81956 CVSS 7.8 high Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81955 CVSS 8.8 high Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-81954 CVSS 7.8 high Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81953 CVSS 7.8 high Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81952 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-81951 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81950 CVSS 7.8 high Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81949 CVSS 7.8 high Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81948 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81947 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81401 CVSS 5.5 medium Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose…
- CVE-2026-81400 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81399 CVSS 5.5 medium Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81398 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81397 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81396 CVSS 7.8 high Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81395 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81394 CVSS 5.5 medium Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to…
- CVE-2026-81393 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81392 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81391 CVSS 5.5 medium Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.