SB2026090916 - Multiple vulnerabilities in Microsoft Office
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 105 vulnerabilities.
1) External Control of File Name or Path (CVE-ID: CVE-2026-62804)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute code locally.
The vulnerability exists due to external control of file name or path in Microsoft Office Word when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute code locally.
The Preview Pane is not an attack vector.
2) Insufficiently protected credentials (CVE-ID: CVE-2026-64918)
CWE-ID: CWE-522 - Insufficiently Protected Credentials
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose NTLM hashes.
The vulnerability exists due to insufficiently protected credentials in Microsoft Office when a user interacts with a file. A remote attacker can induce a user to interact with a file to disclose NTLM hashes.
Interactions that trigger the leakage include opening the parent folder in Explorer, clicking, dragging, or deleting the file.
3) Heap-based buffer overflow (CVE-ID: CVE-2026-69285)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office when opening a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
The Preview Pane is an attack vector, and user interaction is required.
4) Heap-based buffer overflow (CVE-ID: CVE-2026-69442)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office when a user opens a specially crafted file received from the attacker. A remote attacker can send a specially crafted file to #IMPACT#.
The Preview Pane is not an attack vector.
5) Heap-based buffer overflow (CVE-ID: CVE-2026-69477)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Access when opening a crafted file. A local user can send a crafted file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
6) Heap-based buffer overflow (CVE-ID: CVE-2026-69529)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Access when processing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
7) Heap-based buffer overflow (CVE-ID: CVE-2026-69556)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when opening a specially crafted document. A remote attacker can convince a user to open and interact with a specially crafted document to execute arbitrary code.
8) Stack-based buffer overflow (CVE-ID: CVE-2026-69614)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Access when processing specially crafted data pasted or imported by a user. A remote attacker can provide specially crafted data and convince a user to paste or import it to execute arbitrary code.
The Preview Pane is not an attack vector.
9) Buffer over-read (CVE-ID: CVE-2026-69626)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Microsoft Office when processing user-supplied content. A remote attacker can provide crafted content to disclose sensitive information.
The Preview Pane is not an attack vector.
10) Heap-based buffer overflow (CVE-ID: CVE-2026-69629)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Outlook when opening a specially crafted file. A remote attacker can trick a victim into opening a specially crafted file to execute code.
The Preview Pane is also an attack vector.
11) Use-after-free (CVE-ID: CVE-2026-69632)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office when opening or rendering a specially crafted presentation. A remote attacker can send a specially crafted presentation to a user to execute arbitrary code.
The Preview Pane is an attack vector.
12) Heap-based buffer overflow (CVE-ID: CVE-2026-69671)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing a specially crafted document. A remote attacker can convince a user to open and interact with a specially crafted document to execute arbitrary code.
The Preview Pane is not an attack vector.
13) Use-after-free (CVE-ID: CVE-2026-69678)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft PowerPoint when opening or rendering a specially crafted presentation. A remote attacker can send a specially crafted presentation to execute arbitrary code.
The Preview Pane is an attack vector.
14) Stack-based buffer overflow (CVE-ID: CVE-2026-69686)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Word when opening a specially crafted document. A remote attacker can convince a user to open and interact with a specially crafted document to execute arbitrary code.
The Preview Pane is not an attack vector.
15) Buffer over-read (CVE-ID: CVE-2026-69719)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Microsoft Office Word when processing crafted content. A remote attacker can supply crafted content to disclose sensitive information.
The Preview Pane is not an attack vector.
16) Stack-based buffer overflow (CVE-ID: CVE-2026-69722)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Word when opening a specially crafted document. A remote attacker can convince a user to open and interact with a specially crafted document to execute arbitrary code.
The Preview Pane is not an attack vector.
17) Integer overflow (CVE-ID: CVE-2026-69734)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to integer overflow or wraparound in Microsoft Office Word when processing input. A remote attacker can supply input that triggers the integer overflow to disclose sensitive information.
User interaction is required. The Preview Pane is not an attack vector.
18) Out-of-bounds read (CVE-ID: CVE-2026-69739)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office when user interaction occurs. A remote attacker can cause Microsoft Office to read out-of-bounds memory to disclose information.
The Preview Pane is not an attack vector.
19) Integer overflow (CVE-ID: CVE-2026-69742)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in Microsoft Office Publisher when opening a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
20) Stack-based buffer overflow (CVE-ID: CVE-2026-69759)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Word when a user opens a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
21) Heap-based buffer overflow (CVE-ID: CVE-2026-69764)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
User interaction is required to open the specially crafted file. The Preview Pane is not an attack vector.
22) Use-after-free (CVE-ID: CVE-2026-69767)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft PowerPoint when opening a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.
The Preview Pane is also an attack vector.
23) Heap-based buffer overflow (CVE-ID: CVE-2026-69778)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Access when opening a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
24) Use-after-free (CVE-ID: CVE-2026-69797)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office PowerPoint when handling a specially crafted presentation. A remote attacker can send a specially crafted presentation to a user to execute arbitrary code.
The Preview Pane is an attack vector.
25) Type Confusion (CVE-ID: CVE-2026-72938)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to access of a resource using an incompatible type in Microsoft Office PowerPoint when processing PowerPoint content. A remote attacker can cause PowerPoint to process content to disclose information.
The Preview Pane is not an attack vector.
26) Untrusted Pointer Dereference (CVE-ID: CVE-2026-72956)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to untrusted pointer dereference in Microsoft Office PowerPoint when processing user-supplied data. A remote attacker can trigger the untrusted pointer dereference to disclose sensitive information.
User interaction is required. The Preview Pane is not an attack vector.
27) Heap-based buffer overflow (CVE-ID: CVE-2026-72972)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office Word when opening a specially crafted file. A remote attacker can trick a victim into opening a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
28) Heap-based buffer overflow (CVE-ID: CVE-2026-72973)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.
29) Buffer over-read (CVE-ID: CVE-2026-72974)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Microsoft Office Excel when processing Excel content. A remote attacker can exploit the vulnerability to disclose sensitive information.
User interaction is required, and the Preview Pane is not an attack vector.
30) Out-of-bounds read (CVE-ID: CVE-2026-72975)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office PowerPoint when processing a PowerPoint file. A remote attacker can cause PowerPoint to process a file to disclose information.
The Preview Pane is an attack vector, and successful exploitation could expose small portions of heap memory.
31) Out-of-bounds read (CVE-ID: CVE-2026-72976)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when opening a specially crafted file. A local user can open a specially crafted file to disclose sensitive information.
The Preview Pane is not an attack vector.
32) Out-of-bounds read (CVE-ID: CVE-2026-72977)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office PowerPoint when processing PowerPoint content through the Preview Pane. A remote attacker can exploit the vulnerability to disclose information.
User interaction is required.
33) Heap-based buffer overflow (CVE-ID: CVE-2026-77898)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office when processing a crafted Office document. A remote attacker can send a specially crafted Office document to execute arbitrary code.
The Preview Pane is an attack vector.
34) NULL pointer dereference (CVE-ID: CVE-2026-77901)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a null pointer dereference in Microsoft Office Word when opening a specially crafted file. A remote attacker can trick a user into opening a specially crafted file to execute arbitrary code.
35) Out-of-bounds read (CVE-ID: CVE-2026-77911)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when processing crafted input. A remote attacker can send crafted input to disclose sensitive information.
User interaction is required.
36) Out-of-bounds read (CVE-ID: CVE-2026-78502)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when processing input. A remote attacker can provide input for processing to disclose information.
User interaction is required.
37) Out-of-bounds read (CVE-ID: CVE-2026-78503)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when processing user-supplied content. A remote attacker can provide input that triggers the out-of-bounds read to disclose sensitive information.
User interaction is required. The Preview Pane is not an attack vector.
38) Stack-based buffer overflow (CVE-ID: CVE-2026-78504)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Word when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
39) Heap-based buffer overflow (CVE-ID: CVE-2026-78505)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office for macOS when processing a specially crafted Microsoft Office document. A remote attacker can convince a user to open and save a specially crafted Microsoft Office document to execute arbitrary code.
The Preview Pane is an attack vector.
40) Improper Null Termination (CVE-ID: CVE-2026-78506)
CWE-ID: CWE-170 - Improper Null Termination
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper null termination in Microsoft Office Word when processing input. A remote attacker can trigger the improper null termination to disclose sensitive information.
User interaction is required, and the Preview Pane is not an attack vector.
41) Use-after-free (CVE-ID: CVE-2026-78507)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office Word when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
42) Heap-based buffer overflow (CVE-ID: CVE-2026-78509)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Outlook when processing a specially crafted email message. A remote attacker can send a specially crafted email message to execute arbitrary code.
Viewing the message in the Outlook Reading Pane can trigger the vulnerability without the recipient opening the message or clicking anything in it.
43) Heap-based buffer overflow (CVE-ID: CVE-2026-78510)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing a malicious RTF file. A remote attacker can craft a malicious RTF file to execute arbitrary code.
The Preview Pane is an attack vector.
44) Heap-based buffer overflow (CVE-ID: CVE-2026-78511)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing a malicious Office file. A remote attacker can convince a user to open a malicious Office file to execute arbitrary code.
The Preview Pane is not an attack vector.
45) Numeric Truncation Error (CVE-ID: CVE-2026-78512)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to numeric truncation error in Microsoft Office Word when processing a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
46) Out-of-bounds read (CVE-ID: CVE-2026-78513)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office PowerPoint when handling PowerPoint content. A remote attacker can exploit the vulnerability to disclose sensitive information.
The Preview Pane is not an attack vector.
47) Use-after-free (CVE-ID: CVE-2026-78514)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office Word when processing a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is also an attack vector.
48) Out-of-bounds read (CVE-ID: CVE-2026-78515)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when processing an Excel file. A remote attacker can cause Excel to process an Excel file to disclose sensitive information.
The Preview Pane is an attack vector, and disclosed information may include small portions of heap memory.
49) Heap-based buffer overflow (CVE-ID: CVE-2026-78517)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when handling a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
50) Out-of-bounds read (CVE-ID: CVE-2026-78518)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when opening a specially crafted Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
51) Use of uninitialized resource (CVE-ID: CVE-2026-78519)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use of an uninitialized resource in Microsoft Office Outlook when processing a specially crafted email. A remote attacker can send a specially crafted email to a victim to execute arbitrary code.
Exploitation requires the victim to open the email or for Outlook to display its preview.
52) Out-of-bounds read (CVE-ID: CVE-2026-78520)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Outlook when displaying content in the Preview Pane. A remote attacker can exploit the vulnerability to disclose sensitive information.
53) Heap-based buffer overflow (CVE-ID: CVE-2026-78521)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing malicious mail-merge data. A remote attacker can send a specially crafted Word document containing malicious mail-merge data to execute arbitrary code.
User interaction is required to open the document and process or update its mail-merge data. The Preview Pane is not an attack vector.
54) Out-of-bounds read (CVE-ID: CVE-2026-78522)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when processing crafted content. A remote attacker can provide crafted content to disclose sensitive information.
The Preview Pane is not an attack vector.
55) Out-of-bounds write (CVE-ID: CVE-2026-78524)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in Microsoft Office when processing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
56) Use-after-free (CVE-ID: CVE-2026-78525)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office Outlook when processing a specially crafted email. A remote attacker can send a specially crafted email to execute arbitrary code.
The victim must open the specially crafted email or Outlook must display a preview of it.
57) Heap-based buffer overflow (CVE-ID: CVE-2026-78526)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing a specially crafted Word document containing a malicious image. A remote attacker can send a specially crafted Word document to a target user to execute arbitrary code.
User interaction is required to open the document and apply the Artistic Cutout picture effect. The Preview Pane is not an attack vector.
58) Out-of-bounds read (CVE-ID: CVE-2026-80073)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Outlook when using the Preview Pane. A remote attacker can cause an out-of-bounds read to disclose sensitive information.
Successful exploitation could expose small portions of heap memory.
59) Out-of-bounds read (CVE-ID: CVE-2026-80076)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office when processing content received over a network. A remote attacker can induce user interaction with crafted content to disclose sensitive information.
The Preview Pane is not an attack vector.
60) Out-of-bounds read (CVE-ID: CVE-2026-80078)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office for macOS when processing input. A remote attacker can exploit the vulnerability to disclose sensitive information.
User interaction is required. The Preview Pane is not an attack vector.
61) Out-of-bounds read (CVE-ID: CVE-2026-80079)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when opening a crafted file. A remote attacker can trick the victim into opening a crafted Word file to disclose sensitive information.
The Preview Pane is not an attack vector.
62) Double free (CVE-ID: CVE-2026-80080)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a double free in Microsoft Office Word when processing a specially crafted file. A remote attacker can trick a user into opening a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
63) Use-after-free (CVE-ID: CVE-2026-80081)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office PowerPoint when processing a specially crafted PowerPoint presentation containing malicious linked media. A remote attacker can send a specially crafted PowerPoint presentation to a target user to execute arbitrary code.
The victim must open the presentation, start the slideshow, and allow the linked content; the Preview Pane is not an attack vector.
64) Out-of-bounds read (CVE-ID: CVE-2026-80082)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office when processing input. A remote attacker can exploit the vulnerability to disclose sensitive information.
The Preview Pane is not an attack vector.
65) Out-of-bounds read (CVE-ID: CVE-2026-80084)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Outlook when handling attacker-supplied content over a network. A remote attacker can send crafted content to disclose information.
Successful exploitation can expose small portions of heap memory. User interaction is required. The Preview Pane is not an attack vector.
66) Heap-based buffer overflow (CVE-ID: CVE-2026-80085)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when opening and saving or converting a specially crafted Word document. A remote attacker can send a specially crafted Word document to a target user to execute arbitrary code.
User interaction is required to open the document and save or convert it to another format. The Preview Pane is not an attack vector.
67) Out-of-bounds read (CVE-ID: CVE-2026-80086)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office PowerPoint when handling input over a network. A remote attacker can trigger an out-of-bounds read to disclose sensitive information.
The Preview Pane is not an attack vector.
68) Heap-based buffer overflow (CVE-ID: CVE-2026-80087)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office when processing content received over a network. A remote attacker can exploit the heap-based buffer overflow to disclose sensitive information.
User interaction is required. The Preview Pane is not an attack vector.
69) Out-of-bounds read (CVE-ID: CVE-2026-80088)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when processing content. A remote attacker can trigger the out-of-bounds read to disclose sensitive information.
User interaction is required. The Preview Pane is not an attack vector.
70) Out-of-bounds read (CVE-ID: CVE-2026-80089)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office when a user interacts with the application. A remote attacker can cause the application to read out-of-bounds heap memory to disclose information.
Disclosed data may include small portions of heap memory.
71) Out-of-bounds read (CVE-ID: CVE-2026-80090)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Word when processing input. A remote attacker can trigger the out-of-bounds read to disclose sensitive information.
User interaction is required, and the Preview Pane is not an attack vector.
72) Use of uninitialized resource (CVE-ID: CVE-2026-80091)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to use of an uninitialized resource in Microsoft Office when processing content. A remote attacker can trigger processing that uses an uninitialized resource to disclose information.
The disclosed information may include uninitialized heap memory. The Preview Pane is an attack vector, and user interaction is required.
73) Deserialization of Untrusted Data (CVE-ID: CVE-2026-81385)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in Microsoft Office Publisher when opening a specially crafted file. A remote attacker can send a specially crafted file to execute arbitrary code.
The Preview Pane is not an attack vector.
74) Heap-based buffer overflow (CVE-ID: CVE-2026-81386)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince the victim to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
75) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-81387)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel when used locally. A remote attacker can exploit the vulnerability locally to disclose sensitive information.
User interaction is required. Disclosure is limited to memory-related information, specifically a heap address returned by the affected service. The Preview Pane is not an attack vector.
76) Stack-based buffer overflow (CVE-ID: CVE-2026-81388)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Excel when processing a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
77) Heap-based buffer overflow (CVE-ID: CVE-2026-81389)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector. Successful exploitation requires the target system to be configured in a specific manner known to the attacker.
78) Out-of-bounds read (CVE-ID: CVE-2026-81390)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when processing crafted content. A remote attacker can cause Microsoft Office Excel to process crafted content to disclose sensitive information.
The Preview Pane is not an attack vector.
79) Use of uninitialized resource (CVE-ID: CVE-2026-81391)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of an uninitialized resource in Microsoft Office Excel when user interaction occurs. A remote attacker can exploit the vulnerability to disclose sensitive information.
The Preview Pane is not an attack vector.
80) Out-of-bounds read (CVE-ID: CVE-2026-81392)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when processing Excel content. A remote attacker can read portions of process memory to disclose information.
User interaction is required.
81) Out-of-bounds read (CVE-ID: CVE-2026-81393)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when processing Excel content. A remote attacker can cause an out-of-bounds read to disclose sensitive information.
User interaction is required. Disclosed information may include uninitialized heap memory.
82) Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-ID: CVE-2026-81394)
CWE-ID: CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive system information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel when a user opens an Excel file. A remote attacker can exploit the vulnerability to disclose sensitive system information.
The disclosed information may include uninitialized stack memory.
83) Out-of-bounds read (CVE-ID: CVE-2026-81395)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when processing a crafted Excel file. A remote attacker can trick the victim into opening a crafted Excel file to disclose sensitive information.
Disclosed information may include uninitialized heap memory. The Preview Pane is not an attack vector.
84) Stack-based buffer overflow (CVE-ID: CVE-2026-81396)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
85) Heap-based buffer overflow (CVE-ID: CVE-2026-81397)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
86) Heap-based buffer overflow (CVE-ID: CVE-2026-81398)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
87) Buffer over-read (CVE-ID: CVE-2026-81399)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Microsoft Office Excel when processing input. A remote attacker can provide input that triggers the buffer over-read to disclose sensitive information.
User interaction is required. Successfully exploiting the issue can disclose uninitialized stack memory.
88) Out-of-bounds read (CVE-ID: CVE-2026-81400)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when processing input. A remote attacker can exploit the out-of-bounds read to disclose information.
The Preview Pane is not an attack vector.
89) Type Confusion (CVE-ID: CVE-2026-81401)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to access of a resource using an incompatible type in Microsoft Office Excel when processing input. A remote attacker can exploit the type confusion vulnerability to disclose information.
The Preview Pane is not an attack vector.
90) Heap-based buffer overflow (CVE-ID: CVE-2026-81947)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
91) Heap-based buffer overflow (CVE-ID: CVE-2026-81948)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
92) Integer overflow (CVE-ID: CVE-2026-81949)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
93) Double free (CVE-ID: CVE-2026-81950)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to double free in Microsoft Office Excel when processing a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
94) Heap-based buffer overflow (CVE-ID: CVE-2026-81951)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
95) Heap-based buffer overflow (CVE-ID: CVE-2026-81952)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing a malicious RTF file opened by a user. A remote attacker can craft a malicious RTF file and persuade a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
96) Stack-based buffer overflow (CVE-ID: CVE-2026-81953)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
97) Use-after-free (CVE-ID: CVE-2026-81954)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
98) Out-of-bounds read (CVE-ID: CVE-2026-81956)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute code locally.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute code locally.
The Preview Pane is not an attack vector.
99) Out-of-bounds read (CVE-ID: CVE-2026-81957)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
100) Use of uninitialized resource (CVE-ID: CVE-2026-81958)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of an uninitialized resource in Microsoft Office Excel when processing a file. A remote attacker can cause a victim to open a crafted file to disclose sensitive information.
The Preview Pane is not an attack vector.
101) Heap-based buffer overflow (CVE-ID: CVE-2026-81959)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code locally.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Excel when opening a crafted Office file. A remote attacker can send a malicious Office file and convince a victim to open it to execute arbitrary code locally.
The Preview Pane is not an attack vector.
102) Heap-based buffer overflow (CVE-ID: CVE-2026-81960)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute arbitrary code.
The Preview Pane is not an attack vector.
103) Buffer over-read (CVE-ID: CVE-2026-83949)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a buffer over-read in Microsoft Office Word when opening a malicious Office file. A remote attacker can send a malicious Office file to disclose sensitive information.
The Preview Pane can be used as an attack vector.
104) Buffer over-read (CVE-ID: CVE-2026-83951)
CWE-ID: CWE-126 - Buffer over-read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to a buffer over-read in Microsoft Office Word when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to disclose information.
The Preview Pane is not an attack vector.
105) Out-of-bounds read (CVE-ID: CVE-2026-85875)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in Microsoft Office Excel when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to disclose sensitive information.
The Preview Pane is not an attack vector.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62804
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-64918
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69285
- https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69442
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69477
- https://support.microsoft.com/help/5002912
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69529
- https://support.microsoft.com/help/5002913
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69556
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69614
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69626
- https://learn.microsoft.com/en-us/officeupdates/release-notes-office-for-mac
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69629
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69632
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69671
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69678
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69686
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69719
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69722
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69734
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69739
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69742
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69759
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69764
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69767
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69778
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69797
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72938
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72956
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72972
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72973
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72974
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72975
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72976
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-72977
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77898
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77901
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-77911
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78502
- https://support.microsoft.com/help/5002923
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78503
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78504
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78505
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78506
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78507
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78509
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78510
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78511
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78512
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78513
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78514
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78515
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78517
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78518
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78519
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78520
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78521
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78522
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78524
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78525
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78526
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80073
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80076
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80078
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80079
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80080
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80081
- https://docs.microsoft.com/en-us/officeupdates/office365-proplus-security-updates
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80082
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80084
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80085
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80086
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80087
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80088
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80089
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80090
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80091
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81385
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81386
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81387
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81388
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81389
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81390
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81391
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81392
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81393
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81394
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81395
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81396
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81397
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81398
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81399
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81400
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81401
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81947
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81948
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81949
- https://support.microsoft.com/help/5002910
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81950
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81951
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81952
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81953
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81954
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81956
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81957
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81958
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81959
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-81960
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83949
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-83951
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-85875
- https://support.microsoft.com/help/5002904