Msrc Microsoft Office 2019 For 32-Bit Editions vulnerabilities
433 known vulnerabilities affecting msrc/microsoft_office_2019_for_32-bit_editions.
Total CVEs
433
CISA KEV
10
actively exploited
Public exploits
9
Exploited in wild
11
Severity breakdown
CRITICAL10HIGH371MEDIUM49LOW3
Vulnerabilities
Page 1 of 22
CVE-2026-26107HIGHCVSS 7.82026-03-10
CVE-2026-26107 [HIGH] CWE-416 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred t
msrc
CVE-2026-26108HIGHCVSS 7.82026-03-10
CVE-2026-26108 [HIGH] CWE-122 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?
Yes. Customers should apply all updates offered for the software
msrc
CVE-2026-26113HIGHCVSS 8.42026-03-10
CVE-2026-26113 [HIGH] CWE-822 Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes
msrc
CVE-2026-26112HIGHCVSS 7.82026-03-10
CVE-2026-26112 [HIGH] CWE-822 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is somet
msrc
CVE-2026-26110HIGHCVSS 8.42026-03-10
CVE-2026-26110 [HIGH] CWE-843 Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. T
msrc
CVE-2026-26109HIGHCVSS 8.42026-03-10
CVE-2026-26109 [HIGH] CWE-125 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referr
msrc
CVE-2026-21260HIGHCVSS 7.52026-02-10
CVE-2026-21260 [HIGH] CWE-200 Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Spoofing Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
FAQ: There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?
Yes. Customers should apply all updates o
msrc
CVE-2026-21259HIGHCVSS 7.82026-02-10
CVE-2026-21259 [HIGH] CWE-122 Microsoft Excel Elevation of Privilege Vulnerability
Microsoft Excel Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
FAQ: Is the Preview Pane an attack vect
msrc
CVE-2026-21511HIGHCVSS 7.52026-02-10
CVE-2026-21511 [HIGH] CWE-502 Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Spoofing Vulnerability
Description: Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes, the Preview Pane is an attack vector.
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit this spoofing vulnerability by using a specially cra
msrc
CVE-2026-21258MEDIUMCVSS 5.52026-02-10
CVE-2026-21258 [MEDIUM] CWE-20 Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Description: Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ: What type of information c
msrc
CVE-2026-21261MEDIUMCVSS 5.52026-02-10
CVE-2026-21261 [MEDIUM] CWE-125 Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Description: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attac
msrc
CVE-2026-20952HIGHCVSS 8.42026-01-13
CVE-2026-20952 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes, the Preview Pane is an attack vector.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The wor
msrc
CVE-2026-20957HIGHCVSS 7.82026-01-13
CVE-2026-20957 [HIGH] CWE-191 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a
msrc
CVE-2026-20950HIGHCVSS 7.82026-01-13
CVE-2026-20950 [HIGH] CWE-416 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred t
msrc
CVE-2026-21509HIGHCVSS 7.8KEV2026-01-13
CVE-2026-21509 [HIGH] CWE-807 Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
Description: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ
msrc
CVE-2026-20948HIGHCVSS 7.82026-01-13
CVE-2026-20948 [HIGH] CWE-822 Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Description: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometime
msrc
CVE-2026-20953HIGHCVSS 8.42026-01-13
CVE-2026-20953 [HIGH] CWE-416 Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as
msrc
CVE-2026-20955HIGHCVSS 7.82026-01-13
CVE-2026-20955 [HIGH] CWE-822 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote c
msrc
CVE-2026-20946HIGHCVSS 7.82026-01-13
CVE-2026-20946 [HIGH] CWE-125 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referr
msrc
CVE-2025-62553HIGHCVSS 7.82025-12-09
CVE-2025-62553 [HIGH] CWE-416 Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ: According to the CVSS metric, the attack vector
msrc
1 / 22Next →