[NEW] [high] Microsoft Office: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Teams, Microsoft Azure Managed Instance, and Microsoft Service Bus to execute arbitrary code, gain elevated privileges, or manipulate data.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Teams, Azure Managed Instance, and Service Bus enable arbitrary code execution, privilege escalation, and data manipulation.
- Who is affected
- Organizations using Microsoft Teams, Azure Managed Instance, or Service Bus are affected.
- Urgency
- High severity due to remote code execution and privilege escalation capabilities in widely-used services.
- Action
- Apply Microsoft security patches to Teams, Azure, and Service Bus components immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Office
Get an email when a new Office advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2692
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-62896 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62918 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65667 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62836 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50515 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalCVE-2026-65667: Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges…nvd
- highCVE-2026-62918: Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized att…nvd
- criticalCVE-2026-62896: Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges…nvd
- highCVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL Managed Insta…nvd
- criticalCVE-2026-50515: Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execut…nvd
- criticalCVE-2026-65667: Microsoft Teams Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-62918: Microsoft Teams Spoofing Vulnerabilitymsrc
- criticalCVE-2026-50515: Azure Service Bus Remote Code Execution Vulnerabilitymsrc
- highCVE-2026-62836: Azure SQL Managed Instance Elevation of Privilege Vulnerabilitymsrc
- criticalCVE-2026-62896: Microsoft Teams Elevation of Privilege Vulnerabilitymsrc
Recent advisories for Microsoft Office
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-70332: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attac…nvd · 2026-08-07
- criticalCVE-2026-70332: Microsoft Office SharePoint Spoofing Vulnerabilitymsrc · 2026-08-06
- high[NEW] [high] Microsoft Excel (2016), Office (2019, 2021 and 2024) and 365 Apps: Vulnerability allows code exec…cert-bund · 2026-08-04
- highCVE-2026-62870: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over …nvd · 2026-08-04
- unknownVulnerability in Microsoft Office (August 3, 2026)cert-fr-avis · 2026-08-03
- critical[NEW] [critical] Microsoft Office products: Multiple vulnerabilitiescert-bund · 2026-07-23
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] jsoup: Vulnerability enables Cross-Site Scripting2026-08-07
- high[NEW] [high] Apache Portable Runtime (APR): Multiple vulnerabilities2026-08-07
- high[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities2026-08-07
- medium[UPDATE] [medium] Golang Go: Multiple vulnerabilities2026-08-07
- high[UPDATE] [high] Linux Kernel: Multiple vulnerabilities2026-08-07