Back to search

Microsoft

Microsoft 365 Apps for Windows (Office 365)

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-07-21

2606 (20131.20152)

Release date
July 14, 2026
Security status
25 high-severity CVEs tracked in the last 90 days. Current version impact is unclear.

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
2606 (20131.20152) 2026-07-14 Release Notes
2605 (20026.20166) 2026-06-09 Release Notes
2604 (19929.20172) 2026-05-14 Release Notes
2604 (19929.20162) 2026-05-12 Release Notes
2603 (19822.20180) 2026-04-14 Release Notes
2602 (19725.20170) 2026-03-10 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-56156 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
Show 3 more
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55949 HIGH (7.8) 2026-07-14 Current versionunclear

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55947 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55898 HIGH (7.1) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55141 HIGH (7.8) 2026-07-14 Current versionunclear

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55140 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.0 - Up to (excluding) 16.0.5561.1000
Show 5 more
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55137 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55136 HIGH (7.8) 2026-07-14 Current versionunclear

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55134 HIGH (7.8) 2026-07-14 Current versionunclear

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 4 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55133 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
Show 2 more
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55132 HIGH (7.8) 2026-07-14 Current versionunclear

Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 4 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55131 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55130 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 1 more
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55129 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.0 - Up to (excluding) 16.0.5561.1000
Show 5 more
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55128 HIGH (7.8) 2026-07-14 Current versionunclear

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 4 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55127 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 4 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55125 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.0 - Up to (excluding) 16.0.5561.1000
Show 5 more
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55123 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 4 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55122 HIGH (7.1) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55120 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 4 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55058 HIGH (7.8) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55056 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.0 - Up to (excluding) 16.0.5561.1000
Show 5 more
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55055 HIGH (7.8) 2026-07-14 Current versionunclear

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 4 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
CVE-2026-55053 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
Show 5 more
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0.0 - Up to (excluding) 16.0.10417.20175
CVE-2026-55049 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.0 - Up to (excluding) 16.0.5561.1000
Show 5 more
  • From (including) 19.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 1.0.0 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
  • From (including) 16.0.1 - Up to (excluding) 16.111.26071215
  • From (including) 16.0.0 - Up to (excluding) 16.111.26071215