Microsoft 365 Apps For Enterprise vulnerabilities
765 known vulnerabilities affecting microsoft/microsoft_365_apps_for_enterprise.
Total CVEs
765
CISA KEV
10
actively exploited
Public exploits
17
Exploited in wild
15
Severity breakdown
CRITICAL7HIGH584MEDIUM164LOW10
Vulnerabilities
Page 3 of 39
CVE-2026-78504P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-78504 [HIGH] CWE-121 CVE-2026-78504: Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69629P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69629 [HIGH] CWE-122 CVE-2026-69629: Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute co
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69442P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20131.202342026-09-08
CVE-2026-69442 [HIGH] CWE-122 CVE-2026-69442: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-78505P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-78505 [HIGH] CWE-122 CVE-2026-78505: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-41106P3HIGHCVSS 8.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2022-11-09
CVE-2022-41106 [HIGH] CVE-2022-41106: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2026-69778P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69778 [HIGH] CWE-122 CVE-2026-69778: Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute cod
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69671P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69671 [HIGH] CWE-122 CVE-2026-69671: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-72972P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-72972 [HIGH] CWE-122 CVE-2026-72972: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69556P3HIGHCVSS 8.8≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-09-08
CVE-2026-69556 [HIGH] CWE-122 CVE-2026-69556: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-72973P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-72973 [HIGH] CWE-122 CVE-2026-72973: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-78511P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-78511 [HIGH] CWE-122 CVE-2026-78511: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-78524P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-78524 [HIGH] CWE-787 CVE-2026-78524: Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a netwo
Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69764P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69764 [HIGH] CWE-122 CVE-2026-69764: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-78525P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-78525 [HIGH] CWE-416 CVE-2026-78525: Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a ne
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69767P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69767 [HIGH] CWE-416 CVE-2026-69767: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69797P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69797 [HIGH] CWE-416 CVE-2026-69797: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69678P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69678 [HIGH] CWE-416 CVE-2026-69678: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69632P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-69632 [HIGH] CWE-416 CVE-2026-69632: Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-80080P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-80080 [HIGH] CWE-415 CVE-2026-80080: Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-78519P3HIGHCVSS 8.8≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-78519 [HIGH] CWE-908 CVE-2026-78519: Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
nvd