Back to search

Microsoft

Microsoft 365 Apps for Windows (Office 365)

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-09-04

2508 (19127.20752)

Release date
August 11, 2026
Security status
100 high-severity CVEs tracked in the last 90 days. Current version impact is unclear.

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
2508 (19127.20752) 2026-08-11 Release Notes
2508 (19127.20730) 2026-07-14 Release Notes
2508 (19127.20678) 2026-06-09 Release Notes
2508 (19127.20648) 2026-05-14 Release Notes
2508 (19127.20646) 2026-05-12 Release Notes
2508 (19127.20622) 2026-04-14 Release Notes
2508 (19127.20570) 2026-03-10 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-70130 HIGH (8.4) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68817 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68814 HIGH (7.8) 2026-08-11 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68812 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68805 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68804 HIGH (7.8) 2026-08-11 Current versionunclear

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68803 HIGH (7.8) 2026-08-11 Current versionunclear

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68801 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68798 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-66807 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64919 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64920 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64915 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64914 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64908 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64911 HIGH (7.8) 2026-08-11 Current versionunclear

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64912 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64910 HIGH (7.8) 2026-08-11 Current versionunclear

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64909 HIGH (7.8) 2026-08-11 Current versionunclear

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64906 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64907 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64905 HIGH (7.8) 2026-08-11 Current versionunclear

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64904 HIGH (7.8) 2026-08-11 Current versionunclear

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64903 HIGH (7.8) 2026-08-11 Current versionunclear

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-64898 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63533 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63532 HIGH (7.8) 2026-08-11 Current versionunclear

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63527 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63526 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63525 HIGH (7.8) 2026-08-11 Current versionunclear

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-58651 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-70329 HIGH (8.8) 2026-08-11 Current versionunclear

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-70313 HIGH (7.8) 2026-08-11 Current versionunclear

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-70311 HIGH (7.8) 2026-08-11 Current versionunclear

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68816 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68815 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68811 HIGH (7.8) 2026-08-11 Current versionunclear

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68810 HIGH (7.8) 2026-08-11 Current versionunclear

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68806 HIGH (7.8) 2026-08-11 Current versionunclear

Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68807 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68800 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68796 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68795 HIGH (7.8) 2026-08-11 Current versionunclear

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68794 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68793 HIGH (7.8) 2026-08-11 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-68792 HIGH (7.8) 2026-08-11 Current versionunclear

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-65807 HIGH (8.8) 2026-08-11 Current versionunclear

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-65664 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-65661 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-65656 HIGH (7.8) 2026-08-11 Current versionunclear

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-65657 HIGH (7.8) 2026-08-11 Current versionunclear

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63519 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63518 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63515 HIGH (7.8) 2026-08-11 Current versionunclear

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-63513 HIGH (7.8) 2026-08-11 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-62870 HIGH (8.8) 2026-08-03 Current versionunclear

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-50665 HIGH (7.8) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-56156 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55949 HIGH (7.8) 2026-07-14 Current versionunclear

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55947 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-54131 HIGH (7.8) 2026-07-14 Current versionunclear

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55120 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55123 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55133 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55043 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55130 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55128 HIGH (7.8) 2026-07-14 Current versionunclear

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55140 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55056 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55134 HIGH (7.8) 2026-07-14 Current versionunclear

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55131 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55122 HIGH (7.1) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55053 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55137 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55132 HIGH (7.8) 2026-07-14 Current versionunclear

Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55038 HIGH (7.8) 2026-07-14 Current versionunclear

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55058 HIGH (7.8) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55037 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55055 HIGH (7.8) 2026-07-14 Current versionunclear

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55044 HIGH (7.8) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55036 HIGH (7.8) 2026-07-14 Current versionunclear

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55129 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55141 HIGH (7.8) 2026-07-14 Current versionunclear

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55136 HIGH (7.8) 2026-07-14 Current versionunclear

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55127 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55041 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55033 HIGH (7.8) 2026-07-14 Current versionunclear

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55032 HIGH (7.8) 2026-07-14 Current versionunclear

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55049 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55045 HIGH (8.4) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55039 HIGH (7.8) 2026-07-14 Current versionunclear

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55029 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55048 HIGH (7.8) 2026-07-14 Current versionunclear

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55031 HIGH (7.8) 2026-07-14 Current versionunclear

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55125 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55025 HIGH (7.8) 2026-07-14 Current versionunclear

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55022 HIGH (7.8) 2026-07-14 Current versionunclear

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55018 HIGH (7.8) 2026-07-14 Current versionunclear

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55024 HIGH (7.8) 2026-07-14 Current versionunclear

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases
CVE-2026-55017 HIGH (7.8) 2026-07-14 Current versionunclear

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected versions
  • From (including) 16.0.1 - Up to (excluding) https://aka.ms/OfficeSecurityReleases

31 further matching CVEs are not displayed. The table shows the 100 most relevant of 131, recently published first.