cbcvebase.

Microsoft 365 Apps For Enterprise vulnerabilities

765 known vulnerabilities affecting microsoft/microsoft_365_apps_for_enterprise.

Total CVEs
765
CISA KEV
10
actively exploited
Public exploits
17
Exploited in wild
15
Severity breakdown
CRITICAL7HIGH584MEDIUM164LOW10

Vulnerabilities

Page 35 of 39
CVE-2026-81958P4MEDIUMCVSS 5.5≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-81958 [MEDIUM] CWE-908 CVE-2026-81958: Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-81393P4MEDIUMCVSS 5.5≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-81393 [MEDIUM] CWE-125 CVE-2026-81393: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-81400P4MEDIUMCVSS 5.5≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-81400 [MEDIUM] CWE-125 CVE-2026-81400: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-81391P4MEDIUMCVSS 5.5≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-81391 [MEDIUM] CWE-908 CVE-2026-81391: Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-85875P4MEDIUMCVSS 5.5≥ 16.0.1, < 16.0.20326.201382026-09-08
CVE-2026-85875 [MEDIUM] CWE-125 CVE-2026-85875: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-70318P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-70318 [MEDIUM] CWE-20 CVE-2026-70318: Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose info Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63531P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63531 [MEDIUM] CWE-125 CVE-2026-63531: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-64917P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-64917 [MEDIUM] CWE-125 CVE-2026-64917: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63528P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63528 [MEDIUM] CWE-125 CVE-2026-63528: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-68799P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-68799 [MEDIUM] CWE-908 CVE-2026-68799: Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63521P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63521 [MEDIUM] CWE-125 CVE-2026-63521: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-70310P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-70310 [MEDIUM] CWE-125 CVE-2026-70310: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-66809P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-66809 [MEDIUM] CWE-125 CVE-2026-66809: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-1583P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1583 [MEDIUM] CVE-2020-1583: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1497P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1497 [MEDIUM] CVE-2020-1497: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2020-1502P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1502 [MEDIUM] CVE-2020-1502: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1503P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1503 [MEDIUM] CVE-2020-1503: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1224P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2020-09-11
CVE-2020-1224 [MEDIUM] CVE-2020-1224: <p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the cont An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2022-24462P4MEDIUMCVSS 5.5≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2022-03-09
CVE-2022-24462 [MEDIUM] CVE-2022-24462: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2026-33822P4MEDIUMCVSS 6.1≥ 16.0.1, < https://aka.ms/OfficeSecurityReleases2026-04-14
CVE-2026-33822 [MEDIUM] CWE-125 CVE-2026-33822: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
Microsoft 365 Apps For Enterprise vulnerabilities | cvebase