Microsoft Word

32 known vulnerabilities in Microsoft Word, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2023-36761 CVSS 6.5 medium ยท actively exploited Microsoft Word Information Disclosure Vulnerability

Latest vulnerabilities

  • CVE-2026-83951 CVSS 5.5 medium Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
  • CVE-2026-83949 CVSS 5.5 medium Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
  • CVE-2026-80090 CVSS 6.5 medium Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-80085 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-80080 CVSS 8.8 high Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-80079 CVSS 6.5 medium Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-78525 CVSS 8.8 high Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78522 CVSS 6.5 medium Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-78521 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78520 CVSS 6.5 medium Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78517 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78514 CVSS 8.8 high Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78511 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78509 CVSS 9.8 critical Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78506 CVSS 5.5 medium Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
  • CVE-2026-78504 CVSS 8.8 high Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-78503 CVSS 6.5 medium Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-78502 CVSS 6.5 medium Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-77911 CVSS 6.5 medium Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-77901 CVSS 8.8 high Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-72976 CVSS 5.0 medium Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
  • CVE-2026-72973 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-72972 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-69764 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-69759 CVSS 8.8 high Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-69734 CVSS 6.5 medium Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-69722 CVSS 8.8 high Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-69719 CVSS 6.5 medium Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-69686 CVSS 8.8 high Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
  • CVE-2026-69671 CVSS 8.8 high Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.