Multiple vulnerabilities in Microsoft Office (August 12, 2026)
Multiple vulnerabilities have been discovered in Microsoft Office. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Office enable remote code execution, privilege escalation, and data confidentiality breaches.
- Who is affected
- Users of Microsoft Office with versions affected by CVE-2026-66807, CVE-2026-64911, CVE-2026-70310, CVE-2026-68814, CVE-2026-68799, CVE-2026-62842, CVE-2026-63526, and CVE-2026-63517.
- Urgency
- Highly urgent; remote code execution vulnerabilities in widely-used productivity software pose significant risk.
- Action
- Apply Microsoft August 2026 security patches immediately for all Office installations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Office
Get an email when a new Office advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1000/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-668070.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-649110.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703100.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-688140.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-687990.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628420.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-635260.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-635170.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703130.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-635270.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Office Products: Multiple Vulnerabilitiescert-bund
- unknownNCSC-2026-0286 [1.00] [M/H] Vulnerabilities patched in Microsoft Officencsc-nl
- mediumCVE-2026-70327: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose infor…nvd
- mediumCVE-2026-70323: Improper input validation in Microsoft Office allows an unauthorized attacker to disclose info…nvd
- mediumCVE-2026-70320: Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to di…nvd
- mediumCVE-2026-70319: Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose…nvd
- mediumCVE-2026-70316: Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to di…nvd
- highCVE-2026-70313: Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to di…nvd
- mediumCVE-2026-70312: Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to di…nvd
- highCVE-2026-70311: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locall…nvd
- mediumCVE-2026-70310: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose inform…nvd
- highCVE-2026-68817: Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execu…nvd
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14