[NEU] [hoch] Microsoft Office Produkte: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in verschiedenen Microsoft Office Produkten, Microsoft Office Online Server, Microsoft 365 Apps, Microsoft SharePoint, Microsoft Teams und Microsoft Skype ausnutzen, um erhöhte Berechtigungen zu erlangen, um Code auszuführen, um Informationen offenzulegen und um den Nutzer zu täuschen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3234
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-819510.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819470.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819480.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819490.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819500.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819540.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819560.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819530.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819600.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819580.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans Microsoft Office (09 septembre 2026)cert-fr-avis
- unknownNCSC-2026-0352 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Officencsc-nl
- mediumCVE-2026-85875: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose infor…nvd
- mediumCVE-2026-83951: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose informat…nvd
- mediumCVE-2026-83949: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose informat…nvd
- highCVE-2026-81960: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execut…nvd
- highCVE-2026-81959: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execut…nvd
- mediumCVE-2026-81958: Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to dis…nvd
- highCVE-2026-81957: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code l…nvd
- highCVE-2026-81956: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code l…nvd
- highCVE-2026-81954: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code local…nvd
- highCVE-2026-81953: Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execu…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10