{"schema_version":1,"title":"Microsoft Office vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 103 vulnerabilities in Microsoft Office: 0 in the last 7 days and 40 in the last 90 days, 34 of them critical and 32 exploited in the wild. The most recent, CVE-2026-80091, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/office","json_url":"https://junglewise.ai/threats/technologies/office.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/office","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":50,"all_time":103,"critical":34,"exploited":32,"last_7_days":0,"last_30_days":16,"last_90_days":40,"last_365_days":70},"latest":[{"cve":"CVE-2026-80091","cvss":6.5,"epss":0.0092,"slug":"cve-2026-80091-microsoft-office-use-of-uninitialized-resource","title":"Microsoft Office use of uninitialized resource","severity":"medium","exploited":false,"published_at":"2026-09-08T18:20:51.68+00:00","url":"https://junglewise.ai/threats/cve-2026-80091-microsoft-office-use-of-uninitialized-resource"},{"cve":"CVE-2026-80089","cvss":6.5,"epss":0.0092,"slug":"cve-2026-80089-microsoft-office-out-of-bounds-read-information-disclosure","title":"Microsoft Office out-of-bounds read information disclosure","severity":"medium","exploited":false,"published_at":"2026-09-08T18:20:51.41+00:00","url":"https://junglewise.ai/threats/cve-2026-80089-microsoft-office-out-of-bounds-read-information-disclosure"},{"cve":"CVE-2026-80087","cvss":6.5,"epss":0.0092,"slug":"cve-2026-80087-microsoft-office-heap-based-buffer-overflow","title":"Microsoft Office heap-based buffer overflow","severity":"medium","exploited":false,"published_at":"2026-09-08T18:20:51.15+00:00","url":"https://junglewise.ai/threats/cve-2026-80087-microsoft-office-heap-based-buffer-overflow"},{"cve":"CVE-2026-80082","cvss":6.5,"epss":0.0092,"slug":"cve-2026-80082-microsoft-office-out-of-bounds-read","title":"Microsoft Office out-of-bounds read","severity":"medium","exploited":false,"published_at":"2026-09-08T18:20:50.487+00:00","url":"https://junglewise.ai/threats/cve-2026-80082-microsoft-office-out-of-bounds-read"},{"cve":"CVE-2026-80078","cvss":6.5,"epss":0.0092,"slug":"cve-2026-80078-microsoft-office-out-of-bounds-read","title":"Microsoft Office out-of-bounds read","severity":"medium","exploited":false,"published_at":"2026-09-08T18:20:49.98+00:00","url":"https://junglewise.ai/threats/cve-2026-80078-microsoft-office-out-of-bounds-read"},{"cve":"CVE-2026-80076","cvss":6.5,"epss":0.0092,"slug":"cve-2026-80076-microsoft-office-out-of-bounds-read-in-memory-parsing","title":"Microsoft Office out-of-bounds read in memory parsing","severity":"medium","exploited":false,"published_at":"2026-09-08T18:20:49.723+00:00","url":"https://junglewise.ai/threats/cve-2026-80076-microsoft-office-out-of-bounds-read-in-memory-parsing"},{"cve":"CVE-2026-78524","cvss":8.8,"epss":0.0082,"slug":"cve-2026-78524-microsoft-office-out-of-bounds-write-in-document-handling","title":"Microsoft Office out-of-bounds write in document handling","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:48.1+00:00","url":"https://junglewise.ai/threats/cve-2026-78524-microsoft-office-out-of-bounds-write-in-document-handling"},{"cve":"CVE-2026-78510","cvss":8.4,"epss":0.0097,"slug":"cve-2026-78510-microsoft-office-heap-based-buffer-overflow-allows-code-execution","title":"Microsoft Office heap-based buffer overflow allows code execution","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:46.2+00:00","url":"https://junglewise.ai/threats/cve-2026-78510-microsoft-office-heap-based-buffer-overflow-allows-code-execution"},{"cve":"CVE-2026-78505","cvss":8.8,"epss":0.0082,"slug":"cve-2026-78505-microsoft-office-heap-based-buffer-overflow","title":"Microsoft Office heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:45.487+00:00","url":"https://junglewise.ai/threats/cve-2026-78505-microsoft-office-heap-based-buffer-overflow"},{"cve":"CVE-2026-77898","cvss":7.5,"epss":0.0061,"slug":"cve-2026-77898-microsoft-office-heap-based-buffer-overflow","title":"Microsoft Office heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:39.98+00:00","url":"https://junglewise.ai/threats/cve-2026-77898-microsoft-office-heap-based-buffer-overflow"},{"cve":"CVE-2026-69739","cvss":6.5,"epss":0.0092,"slug":"cve-2026-69739-microsoft-office-out-of-bounds-read-information-disclosure","title":"Microsoft Office out-of-bounds read information disclosure","severity":"medium","exploited":false,"published_at":"2026-09-08T18:19:46.113+00:00","url":"https://junglewise.ai/threats/cve-2026-69739-microsoft-office-out-of-bounds-read-information-disclosure"},{"cve":"CVE-2026-69632","cvss":8.8,"epss":0.0082,"slug":"cve-2026-69632-microsoft-office-use-after-free-in-remote-code-execution","title":"Microsoft Office use-after-free in remote code execution","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:35.74+00:00","url":"https://junglewise.ai/threats/cve-2026-69632-microsoft-office-use-after-free-in-remote-code-execution"},{"cve":"CVE-2026-69626","cvss":6.5,"epss":0.0092,"slug":"cve-2026-69626-microsoft-office-buffer-over-read-information-disclosure","title":"Microsoft Office buffer over-read information disclosure","severity":"medium","exploited":false,"published_at":"2026-09-08T18:19:34.81+00:00","url":"https://junglewise.ai/threats/cve-2026-69626-microsoft-office-buffer-over-read-information-disclosure"},{"cve":"CVE-2026-69442","cvss":8.8,"epss":0.0082,"slug":"cve-2026-69442-microsoft-office-heap-based-buffer-overflow","title":"Microsoft Office heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:08.413+00:00","url":"https://junglewise.ai/threats/cve-2026-69442-microsoft-office-heap-based-buffer-overflow"},{"cve":"CVE-2026-69285","cvss":8.8,"epss":0.0082,"slug":"cve-2026-69285-microsoft-office-heap-based-buffer-overflow","title":"Microsoft Office heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:18:43.203+00:00","url":"https://junglewise.ai/threats/cve-2026-69285-microsoft-office-heap-based-buffer-overflow"},{"cve":"CVE-2026-64918","cvss":6.5,"epss":0.0087,"slug":"cve-2026-64918-microsoft-office-insufficiently-protected-credentials-spoofing","title":"Microsoft Office insufficiently protected credentials spoofing","severity":"medium","exploited":false,"published_at":"2026-09-08T18:18:13.72+00:00","url":"https://junglewise.ai/threats/cve-2026-64918-microsoft-office-insufficiently-protected-credentials-spoofing"},{"cve":"CVE-2026-70130","cvss":8.4,"epss":0.0034,"slug":"cve-2026-70130-microsoft-office-heap-based-buffer-overflow","title":"Microsoft Office heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-11T17:19:07.653+00:00","url":"https://junglewise.ai/threats/cve-2026-70130-microsoft-office-heap-based-buffer-overflow"},{"cve":"CVE-2026-68792","cvss":7.8,"epss":0.0032,"slug":"cve-2026-68792-microsoft-office-command-injection-in-privilege-escalation","title":"Microsoft Office command injection in privilege escalation","severity":"high","exploited":false,"published_at":"2026-08-11T17:19:02.627+00:00","url":"https://junglewise.ai/threats/cve-2026-68792-microsoft-office-command-injection-in-privilege-escalation"},{"cve":"CVE-2026-66809","cvss":5.5,"epss":0.0044,"slug":"cve-2026-66809-microsoft-office-out-of-bounds-read-information-disclosure","title":"Microsoft Office out-of-bounds read information disclosure","severity":"medium","exploited":false,"published_at":"2026-08-11T17:19:02.36+00:00","url":"https://junglewise.ai/threats/cve-2026-66809-microsoft-office-out-of-bounds-read-information-disclosure"},{"cve":"CVE-2026-66807","cvss":7.8,"epss":0.0047,"slug":"cve-2026-66807-microsoft-office-stack-based-buffer-overflow","title":"Microsoft Office stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-11T17:19:02.107+00:00","url":"https://junglewise.ai/threats/cve-2026-66807-microsoft-office-stack-based-buffer-overflow"},{"cve":"CVE-2026-65664","cvss":7.8,"epss":0.0047,"slug":"cve-2026-65664-microsoft-office-heap-buffer-overflow","title":"Microsoft Office heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-11T17:18:54.633+00:00","url":"https://junglewise.ai/threats/cve-2026-65664-microsoft-office-heap-buffer-overflow"},{"cve":"CVE-2026-65661","cvss":7.8,"epss":0.0047,"slug":"cve-2026-65661-microsoft-office-heap-buffer-overflow","title":"Microsoft Office heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-11T17:18:54.203+00:00","url":"https://junglewise.ai/threats/cve-2026-65661-microsoft-office-heap-buffer-overflow"},{"cve":"CVE-2026-65657","cvss":7.8,"epss":0.0047,"slug":"cve-2026-65657-microsoft-office-use-after-free-local-code-execution","title":"Microsoft Office use after free local code execution","severity":"high","exploited":false,"published_at":"2026-08-11T17:18:53.83+00:00","url":"https://junglewise.ai/threats/cve-2026-65657-microsoft-office-use-after-free-local-code-execution"},{"cve":"CVE-2026-65656","cvss":7.8,"epss":0.0046,"slug":"cve-2026-65656-microsoft-office-command-injection-vulnerability","title":"Microsoft Office command injection vulnerability","severity":"high","exploited":false,"published_at":"2026-08-11T17:18:53.703+00:00","url":"https://junglewise.ai/threats/cve-2026-65656-microsoft-office-command-injection-vulnerability"},{"cve":"CVE-2026-64911","cvss":7.8,"epss":0.0047,"slug":"cve-2026-64911-microsoft-office-integer-overflow-or-wraparound","title":"Microsoft Office integer overflow or wraparound","severity":"high","exploited":false,"published_at":"2026-08-11T17:18:52.28+00:00","url":"https://junglewise.ai/threats/cve-2026-64911-microsoft-office-integer-overflow-or-wraparound"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":24},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":16},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":963,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":167,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"}],"technology":{"hub":true,"name":"Microsoft Office","slug":"office","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":["office-2003","office-2007","office-2010"],"category":"software-suite","homepage":"https://www.microsoft.com/en-us/microsoft-365/office-resources","description":"A suite of productivity applications including word processing, spreadsheets, and presentation software.","url":"https://junglewise.ai/threats/technologies/office"},"most_severe":[{"cve":"CVE-2023-23397","cvss":9.8,"slug":"cve-2023-23397-microsoft-office-outlook-privilege-escalation-vulnerability","title":"Microsoft Office Outlook Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-03-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-23397-microsoft-office-outlook-privilege-escalation-vulnerability"},{"cve":"CVE-2009-0238","cvss":9.3,"epss":0.7491,"slug":"cve-2009-0238-microsoft-excel-remote-code-execution-via-malformed-object","title":"Microsoft Excel remote code execution via malformed object","severity":"critical","exploited":true,"published_at":"2026-04-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2009-0238-microsoft-excel-remote-code-execution-via-malformed-object"},{"cve":"CVE-2009-0557","cvss":9.3,"slug":"cve-2009-0557-microsoft-office-object-record-corruption-vulnerability","title":"Microsoft Office Object Record Corruption Vulnerability","severity":"critical","exploited":true,"published_at":"2022-06-08T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2009-0557-microsoft-office-object-record-corruption-vulnerability"},{"cve":"CVE-2015-1671","cvss":9.3,"slug":"cve-2015-1671-microsoft-windows-remote-code-execution-vulnerability","title":"Microsoft Windows Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2015-1671-microsoft-windows-remote-code-execution-vulnerability"},{"cve":"CVE-2010-3333","cvss":9.3,"slug":"cve-2010-3333-microsoft-office-stack-based-buffer-overflow-vulnerability","title":"Microsoft Office Stack-based Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2010-3333-microsoft-office-stack-based-buffer-overflow-vulnerability"},{"cve":"CVE-2015-1641","cvss":9.3,"slug":"cve-2015-1641-microsoft-office-memory-corruption-vulnerability","title":"Microsoft Office Memory Corruption Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2015-1641-microsoft-office-memory-corruption-vulnerability"},{"cve":"CVE-2009-0556","cvss":8.8,"epss":0.6788,"slug":"cve-2009-0556-microsoft-powerpoint-code-injection-in-outlinetextrefatom","title":"Microsoft PowerPoint code injection in OutlineTextRefAtom","severity":"critical","exploited":true,"published_at":"2026-01-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2009-0556-microsoft-powerpoint-code-injection-in-outlinetextrefatom"},{"cve":"CVE-2007-0671","cvss":8.8,"epss":0.5549,"slug":"cve-2007-0671-microsoft-office-excel-remote-code-execution-vulnerability","title":"Microsoft Office Excel remote code execution vulnerability","severity":"critical","exploited":true,"published_at":"2025-08-12T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2007-0671-microsoft-office-excel-remote-code-execution-vulnerability"},{"cve":"CVE-2015-1770","cvss":8.8,"slug":"cve-2015-1770-microsoft-office-uninitialized-memory-use-vulnerability","title":"Microsoft Office Uninitialized Memory Use Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2015-1770-microsoft-office-uninitialized-memory-use-vulnerability"},{"cve":"CVE-2012-1856","cvss":8.8,"slug":"cve-2012-1856-microsoft-office-mscomctl-ocx-remote-code-execution-vulnerability","title":"Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2012-1856-microsoft-office-mscomctl-ocx-remote-code-execution-vulnerability"}],"generated_at":"2026-09-26T09:24:00.138874+00:00"}