[NEW] [high] Microsoft Office: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Teams, Microsoft Azure Managed Instance, and Microsoft Service Bus to execute arbitrary code, gain elevated privileges, or manipulate data.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Teams, Azure Managed Instance, and Service Bus enable arbitrary code execution, privilege escalation, and data manipulation.
- Who is affected
- Organizations using Microsoft Teams, Azure Managed Instance, or Service Bus are affected.
- Urgency
- High severity due to remote code execution and privilege escalation capabilities in widely-used services.
- Action
- Apply Microsoft security patches to Teams, Azure, and Service Bus components immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Office
Get an email when a new Office advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2692
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-628960.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-629180.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-656670.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628360.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-505151.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-62896 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62918 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65667 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62836 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50515 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0286 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Officencsc-nl
- unknownNCSC-2026-0286 [1.00] [M/H] Vulnerabilities patched in Microsoft Officencsc-nl
- criticalCVE-2026-50515: Azure Service Bus Remote Code Execution Vulnerabilitymsrc
- highCVE-2026-62836: Azure SQL Managed Instance Elevation of Privilege Vulnerabilitymsrc
- criticalCVE-2026-65667: Microsoft Teams Elevation of Privilege Vulnerabilitymsrc
- criticalCVE-2026-62896: Microsoft Teams Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-62918: Microsoft Teams Spoofing Vulnerabilitymsrc
- criticalCVE-2026-65667: Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges…nvd
- highCVE-2026-62918: Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized att…nvd
- criticalCVE-2026-62896: Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges…nvd
- highCVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL Managed Insta…nvd
- criticalCVE-2026-50515: Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execut…nvd
Recent advisories for Microsoft Office
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEU] [hoch] Microsoft Office Produkte: Mehrere Schwachstellencert-bund · 2026-09-09
- unknownMultiples vulnérabilités dans Microsoft Office (09 septembre 2026)cert-fr-avis · 2026-09-09
- unknownNCSC-2026-0352 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Officencsc-nl · 2026-09-08
- mediumCVE-2026-85875: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose infor…nvd · 2026-09-08
- mediumCVE-2026-83951: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose informat…nvd · 2026-09-08
- mediumCVE-2026-83949: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose informat…nvd · 2026-09-08
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14