SB20260812234 - Multiple vulnerabilities in Microsoft Office



SB20260812234 - Multiple vulnerabilities in Microsoft Office

Published: August 12, 2026

Security Bulletin ID SB20260812234
CSH Severity
High
Patch available
YES
Number of vulnerabilities 79
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 58% Medium 34% Low 8%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 79 vulnerabilities.


1) Out-of-bounds read (CVE-ID: CVE-2026-63530)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Word when parsing a specially crafted Office file. A remote attacker can send a specially crafted Office file to disclose sensitive information.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


2) Stack-based buffer overflow (CVE-ID: CVE-2026-64907)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file.


3) Buffer over-read (CVE-ID: CVE-2026-64905)

CWE-ID: CWE-126 - Buffer over-read

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to buffer over-read in Microsoft Office Word when parsing a specially crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


4) Type Confusion (CVE-ID: CVE-2026-64904)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Office for macOS when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


5) Integer overflow (CVE-ID: CVE-2026-64903)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer overflow or wraparound in Microsoft Office for macOS when parsing a crafted Office file. A remote attacker can send a specially crafted file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane can be used as an attack vector.


6) Out-of-bounds read (CVE-ID: CVE-2026-64899)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office for macOS when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to disclose sensitive information.

The Preview Pane is an attack vector, and user interaction is required to open or preview the crafted file.


7) Heap-based buffer overflow (CVE-ID: CVE-2026-64898)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office for macOS when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open or preview the crafted file, and the Preview Pane is an attack vector.


8) Heap-based buffer overflow (CVE-ID: CVE-2026-63533)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office for macOS when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open or preview the crafted file, and the Preview Pane is an attack vector.


9) Integer overflow (CVE-ID: CVE-2026-63532)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer overflow or wraparound in Microsoft Office for macOS when parsing a specially crafted Office file. A remote attacker can send a specially crafted file to the victim and convince them to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is also an attack vector.


10) Out-of-bounds read (CVE-ID: CVE-2026-63531)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Word when parsing a crafted Office file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed data may include portions of process memory. The Preview Pane is not an attack vector.


11) Integer underflow (CVE-ID: CVE-2026-64909)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer underflow in Microsoft Office when parsing a crafted Office file. A remote attacker can send a specially crafted file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane can be used as an attack vector.


12) Out-of-bounds read (CVE-ID: CVE-2026-63529)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office when parsing a crafted Office file. A remote attacker can send a specially crafted file to the victim to disclose sensitive information.

User interaction is required to open or preview the crafted file, and the Preview Pane can be used as an attack vector.


13) Stack-based buffer overflow (CVE-ID: CVE-2026-63527)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


14) Out-of-bounds read (CVE-ID: CVE-2026-63528)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Word when parsing a crafted Office file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

An attacker who successfully exploits this issue could read portions of process memory. The Preview Pane is not an attack vector for this vulnerability.


15) Stack-based buffer overflow (CVE-ID: CVE-2026-63526)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in the Microsoft Office graphics component when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open or preview it to execute arbitrary code.

The Preview Pane is an attack vector, and user interaction is required.


16) Numeric Truncation Error (CVE-ID: CVE-2026-63525)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to numeric truncation error in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted file and trick the victim into opening it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


17) Out-of-bounds read (CVE-ID: CVE-2026-63524)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office when parsing a crafted Office file. A remote attacker can send a specially crafted file to the victim to disclose sensitive information.

User interaction is required to open or preview the crafted file, and the Preview Pane is an attack vector.


18) Out-of-bounds read (CVE-ID: CVE-2026-62842)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in the Microsoft Office graphics component when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed information may include portions of process memory. The Preview Pane is not an attack vector for this vulnerability.


19) Heap-based buffer overflow (CVE-ID: CVE-2026-58651)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


20) Integer overflow (CVE-ID: CVE-2026-70329)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer overflow or wraparound in Microsoft Office Outlook when processing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file.


21) Out-of-bounds read (CVE-ID: CVE-2026-68797)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The Preview Pane is not an attack vector. Successful exploitation could allow reading portions of process memory.


22) Stack-based buffer overflow (CVE-ID: CVE-2026-68817)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to the victim and convince them to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


23) Out-of-bounds read (CVE-ID: CVE-2026-68814)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


24) Heap-based buffer overflow (CVE-ID: CVE-2026-68812)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to a user and convince them to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


25) Heap-based buffer overflow (CVE-ID: CVE-2026-68805)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

User interaction is required to open a crafted Office file, and the Preview Pane is not an attack vector.


26) Numeric Truncation Error (CVE-ID: CVE-2026-68804)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to numeric truncation error in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted file and convince a user to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


27) Type Confusion (CVE-ID: CVE-2026-68803)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the user to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


28) Heap-based buffer overflow (CVE-ID: CVE-2026-68801)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can trick the victim into opening a specially crafted Office file to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


29) Use of uninitialized resource (CVE-ID: CVE-2026-68799)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of an uninitialized resource in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The disclosed information may include portions of process memory. The Preview Pane is not an attack vector.


30) Heap-based buffer overflow (CVE-ID: CVE-2026-68798)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


31) Out-of-bounds read (CVE-ID: CVE-2026-70328)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The Preview Pane is not an attack vector. Successful exploitation could allow reading portions of process memory.


32) Out-of-bounds read (CVE-ID: CVE-2026-66809)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office graphics component when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The Preview Pane is not an attack vector for this vulnerability.


33) Heap-based buffer overflow (CVE-ID: CVE-2026-66810)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Word when parsing a crafted document. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The disclosed information may include portions of process memory. The Preview Pane is not an attack vector for this vulnerability.


34) Stack-based buffer overflow (CVE-ID: CVE-2026-66807)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Office Graphics Component when parsing a crafted Office file. A remote attacker can send a specially crafted file to execute arbitrary code.

User interaction is required to open or preview the crafted file, and the Preview Pane is an attack vector.


35) Off-by-one (CVE-ID: CVE-2026-66806)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to off-by-one error in Microsoft Office Word when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed information may include portions of process memory. The Preview Pane is not an attack vector.


36) Insufficiently protected credentials (CVE-ID: CVE-2026-62882)

CWE-ID: CWE-522 - Insufficiently Protected Credentials

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to insufficiently protected credentials in Microsoft Office Outlook when processing a malicious Office file. A remote attacker can send a specially crafted Office file to perform spoofing.

User interaction is required to open the crafted file.


37) Out-of-bounds read (CVE-ID: CVE-2026-64917)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted file and convince the victim to open it to disclose sensitive information.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


38) Heap-based buffer overflow (CVE-ID: CVE-2026-64915)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


39) Integer overflow (CVE-ID: CVE-2026-64911)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer overflow or wraparound in Microsoft Office for macOS when parsing a crafted Office file. A remote attacker can send a specially crafted file to the victim and convince them to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


40) Untrusted Pointer Dereference (CVE-ID: CVE-2026-64910)

CWE-ID: CWE-822 - Untrusted Pointer Dereference

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to untrusted pointer dereference in Microsoft Office when parsing a crafted Office file. A remote attacker can send a specially crafted file to a victim and convince them to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


41) Out-of-bounds read (CVE-ID: CVE-2026-68793)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted Office file. A remote attacker can send a malicious Office file and convince the user to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


42) Untrusted Pointer Dereference (CVE-ID: CVE-2026-68810)

CWE-ID: CWE-822 - Untrusted Pointer Dereference

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to untrusted pointer dereference in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted file and convince the victim to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


43) Out-of-bounds read (CVE-ID: CVE-2026-68808)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The Preview Pane is not an attack vector. User interaction is required to open a crafted file.


44) Out-of-bounds write (CVE-ID: CVE-2026-68806)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


45) Heap-based buffer overflow (CVE-ID: CVE-2026-68807)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


46) Out-of-bounds read (CVE-ID: CVE-2026-68802)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The Preview Pane is not an attack vector. User interaction is required to open a crafted file. Successful exploitation could allow reading portions of process memory.


47) Heap-based buffer overflow (CVE-ID: CVE-2026-68800)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince a user to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


48) Heap-based buffer overflow (CVE-ID: CVE-2026-68796)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a specially crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


49) Stack-based buffer overflow (CVE-ID: CVE-2026-68795)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


50) Heap-based buffer overflow (CVE-ID: CVE-2026-68794)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


51) Type Confusion (CVE-ID: CVE-2026-68811)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted file and convince the user to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


52) Type Confusion (CVE-ID: CVE-2026-65807)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Excel when parsing a specially crafted file. A remote attacker can send a specially crafted file to the victim to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


53) Heap-based buffer overflow (CVE-ID: CVE-2026-65664)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office graphics component when parsing a specially crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


54) Heap-based buffer overflow (CVE-ID: CVE-2026-65661)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file.


55) Use-after-free (CVE-ID: CVE-2026-65657)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in Microsoft Office when parsing a crafted Office file. A remote attacker can send a specially crafted file to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is an attack vector.


56) Heap-based buffer overflow (CVE-ID: CVE-2026-63519)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in the Microsoft Office graphics component when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

The Preview Pane is also an attack vector, and user interaction is required.


57) Out-of-bounds read (CVE-ID: CVE-2026-63521)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Word when parsing a crafted document. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The disclosed information may include portions of process memory. The Preview Pane is not an attack vector for this vulnerability.


58) Heap-based buffer overflow (CVE-ID: CVE-2026-63518)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open the crafted file.


59) Out-of-bounds read (CVE-ID: CVE-2026-63517)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Graphics Component when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to cause the application to disclose sensitive information.

User interaction is required to open or preview a crafted Office file, and the Preview Pane can be used as an attack vector. Successful exploitation could expose portions of process memory.


60) Out-of-bounds read (CVE-ID: CVE-2026-63515)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds read in Microsoft Office when parsing a crafted Office file. A remote attacker can send a specially crafted file to a user to execute arbitrary code.

The Preview Pane is an attack vector, and user interaction is required to open or preview the crafted file.


61) Out-of-bounds read (CVE-ID: CVE-2026-70315)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office when processing a specially crafted file in the Preview Pane. A remote attacker can trick the victim into viewing a crafted file to disclose sensitive information.

The disclosed data is limited to small portions of heap memory. User interaction is required to view the crafted content.


62) Out-of-bounds read (CVE-ID: CVE-2026-70327)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The Preview Pane is not an attack vector, and successful exploitation could expose portions of process memory.


63) Input validation error (CVE-ID: CVE-2026-70322)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office PowerPoint when parsing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The disclosed data is limited to small portions of heap memory, and the Preview Pane is not an attack vector.


64) Input validation error (CVE-ID: CVE-2026-70323)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed data is limited to small portions of heap memory. The Preview Pane is not an attack vector for this vulnerability.


65) Input validation error (CVE-ID: CVE-2026-70320)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office PowerPoint when parsing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The disclosed information may include small portions of heap memory. The Preview Pane is not an attack vector for this vulnerability.


66) Input validation error (CVE-ID: CVE-2026-70319)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office Word when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed information is limited to small portions of heap memory. The Preview Pane is not an attack vector.


67) Input validation error (CVE-ID: CVE-2026-70325)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office PowerPoint when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed data may include small portions of heap memory. The Preview Pane is not an attack vector for this vulnerability.


68) Use of uninitialized resource (CVE-ID: CVE-2026-70317)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized resource in Microsoft Office for macOS when processing a specially crafted file or previewing crafted content in the Preview Pane. A remote attacker can trick the victim into opening or previewing crafted content to disclose sensitive information.

An attacker who successfully exploited this vulnerability could potentially read portions of process memory.


69) Input validation error (CVE-ID: CVE-2026-70314)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed data is limited to small portions of heap memory, and the Preview Pane is not an attack vector.


70) Input validation error (CVE-ID: CVE-2026-70318)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed information may include small portions of heap memory. The Preview Pane is not an attack vector for this vulnerability.


71) Heap-based buffer overflow (CVE-ID: CVE-2026-63513)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in the Microsoft Office graphics component when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.

User interaction is required to open or preview the crafted file, and the Preview Pane is an attack vector.


72) Input validation error (CVE-ID: CVE-2026-70316)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office PowerPoint when parsing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.

The disclosed information is limited to small portions of heap memory, and the Preview Pane is not an attack vector.


73) Out-of-bounds read (CVE-ID: CVE-2026-70310)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Word when parsing a specially crafted document. A remote attacker can trick the victim into opening a specially crafted document to disclose sensitive information.

The Preview Pane is not an attack vector, and successful exploitation could allow reading small portions of heap memory.


74) Input validation error (CVE-ID: CVE-2026-70313)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in Microsoft Office PowerPoint when parsing a crafted Office file. A remote attacker can send a specially crafted file and convince the victim to open it to execute arbitrary code.

User interaction is required to open a crafted Office file, and the Preview Pane is not an attack vector.


75) Use-after-free (CVE-ID: CVE-2026-70311)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in Microsoft Office Word when parsing a crafted Office file. A remote attacker can send a specially crafted file and convince the victim to open it to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


76) Input validation error (CVE-ID: CVE-2026-70312)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Microsoft Office PowerPoint when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The disclosed information is limited to small portions of heap memory. The Preview Pane is not an attack vector for this vulnerability.


77) Stack-based buffer overflow (CVE-ID: CVE-2026-68816)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file and convince the victim to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


78) Heap-based buffer overflow (CVE-ID: CVE-2026-68815)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Excel when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to a user and convince them to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


79) Out-of-bounds read (CVE-ID: CVE-2026-68813)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.

The Preview Pane is not an attack vector. User interaction is required to open a crafted file, and successful exploitation could allow reading portions of process memory.


Remediation

Install update from vendor's website.

References