Technology · Microsoft
Microsoft Word vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 29 vulnerabilities in Microsoft Word: 0 in the last 7 days and 11 in the last 90 days, 6 of them critical and 6 exploited in the wild. The most recent, CVE-2026-78511, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 6
- Exploited in the wild
- 6
About Microsoft Word
A word processor developed by Microsoft for creating and editing documents.
Latest Microsoft Word vulnerabilities
- CVE-2026-78511: Microsoft Word heap-based buffer overflowhighCVSS 8.8EPSS 0.8%
- CVE-2026-69764: Microsoft Office Word heap-based buffer overflowhighCVSS 8.8EPSS 0.8%
- CVE-2026-55142: Microsoft Office Word numeric truncation information disclosuremediumCVSS 5.5
- CVE-2026-55134: Microsoft Office Word stack-based buffer overflowhighCVSS 7.8
- CVE-2026-55130: Microsoft Office Word heap buffer overflowhighCVSS 7.8
- CVE-2026-55128: Microsoft Office Word use after free code executionhighCVSS 7.8
- CVE-2026-55127: Microsoft Office Word heap overflow code executionhighCVSS 7.8
- CVE-2026-55124: Microsoft Office Word information disclosure via improper input validationmediumCVSS 5.5
- CVE-2026-55055: Microsoft Office Word stack-based buffer overflowhighCVSS 7.8
- CVE-2026-55038: Microsoft Office Word stack-based buffer overflowhighCVSS 7.8
- CVE-2026-55033: Microsoft Office Word integer overflow code executionhighCVSS 7.8
- CVE-2026-45643: Microsoft Office Word untrusted pointer dereferencehighCVSS 7.8
- CVE-2026-45486: Microsoft Office Word untrusted pointer dereferencehighCVSS 7.8
- CVE-2026-45471: Microsoft Office Word untrusted pointer dereferencehighCVSS 7.8
- CVE-2026-45466: Microsoft Word heap buffer overflow information disclosurelowCVSS 3.3
- CVE-2026-45457: Microsoft Office Word untrusted pointer dereferencehighCVSS 7.8
- CVE-2026-41101: Microsoft Office Word improper access control spoofing vulnerabilityhighCVSS 7.1EPSS 0.0%
- CVE-2026-40421: Microsoft Office Word information disclosure via path traversalmediumCVSS 4.3EPSS 0.1%
- CVE-2026-40367: Microsoft Office Word untrusted pointer dereferencehighCVSS 8.4EPSS 0.1%
- CVE-2026-40366: Microsoft Office Word use after free code executionhighCVSS 8.4EPSS 0.1%
- CVE-2026-40364: Microsoft Office Word type confusion local code executionhighCVSS 8.4EPSS 0.2%
- CVE-2026-40361: Microsoft Office Word use after free code executionhighCVSS 8.4EPSS 0.1%
- CVE-2026-35440: Microsoft Office Word information disclosure via unauthorized file accessmediumCVSS 5.5EPSS 0.0%
- CVE-2026-21514: Microsoft Office Word reliance on untrusted inputs in security decisioncriticalexploited in the wildCVSS 7.8EPSS 4.5%
- CVE-2023-36761: Microsoft Word Information Disclosure Vulnerabilitycriticalexploited in the wildCVSS 6.5
Most severe Microsoft Word vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2012-2539: Microsoft Word Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.3
- CVE-2014-1761: Microsoft Word Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 9.3
- CVE-2006-2492: Microsoft Word Malformed Object Pointer Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2026-21514: Microsoft Office Word reliance on untrusted inputs in security decisioncriticalexploited in the wildCVSS 7.8EPSS 4.5%
- CVE-2017-11826: Microsoft Office Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-2023-36761: Microsoft Word Information Disclosure Vulnerabilitycriticalexploited in the wildCVSS 6.5
- CVE-2026-78511: Microsoft Word heap-based buffer overflowhighCVSS 8.8EPSS 0.8%
- CVE-2026-69764: Microsoft Office Word heap-based buffer overflowhighCVSS 8.8EPSS 0.8%
- CVE-2026-40364: Microsoft Office Word type confusion local code executionhighCVSS 8.4EPSS 0.2%
- CVE-2026-40361: Microsoft Office Word use after free code executionhighCVSS 8.4EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 9 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/word.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft Word vulnerabilities", https://junglewise.ai/threats/technologies/word, 26 September 2026.