Multiple vulnerabilities in Microsoft Office (July 15, 2026)
Multiple vulnerabilities have been discovered in Microsoft Office. They allow an attacker to cause remote arbitrary code execution, privilege escalation, and a data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities could lead to remote code execution, privilege escalation, and data breaches.
- Who is affected
- Users of Microsoft Office.
- Urgency
- Remediation is critical due to the severity of the vulnerabilities.
- Action
- Users should apply the necessary updates to Microsoft Office.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Microsoft Office
Get an email when a new Microsoft Office advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0868/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-476420.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-551340.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-506750.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-550370.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-551300.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-551420.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
- Low exploitation riskCVE-2026-561560.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-550330.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all scored CVEs.
- Low exploitation riskCVE-2026-550260.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-550380.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] Microsoft Office products: Multiple vulnerabilitiescert-bund
- unknownexploitedNCSC-2026-0237 [1.02] [H/H] Vulnerabilities Fixed in Microsoft Officencsc-nl
- unknownexploitedNCSC-2026-0237 [1.01] [H/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- high[NEW] [high] Microsoft Windows Terminal and 365 Copilot: Multiple Vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- unknownexploitedNCSC-2026-0237 [1.00] [M/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- highCVE-2026-58617: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to el…nvd
- highCVE-2026-56156: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execut…nvd
- highCVE-2026-55947: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execut…nvd
- mediumCVE-2026-55142: Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose …nvd
- highCVE-2026-55141: Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execu…nvd
- highCVE-2026-55140: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code…nvd
Recent advisories for Microsoft Office
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEW] [critical] Microsoft Office products: Multiple vulnerabilitiescert-bund · 2026-07-23
- unknownexploitedNCSC-2026-0237 [1.02] [H/H] Vulnerabilities Fixed in Microsoft Officencsc-nl · 2026-07-21
- high[NEW] [high] Microsoft Office 365 (Moodle Plugin): Vulnerability allows bypassing of security measurescert-bund · 2026-07-17
- unknownexploitedNCSC-2026-0237 [1.01] [H/H] Vulnerabilities fixed in Microsoft Officencsc-nl · 2026-07-17
- mediumCVE-2026-62826: Improper neutralization of input during web page generation ('cross-site scripting') in Micros…nvd · 2026-07-16
- unknownCVE-2026-54733: The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Activ…nvd · 2026-07-16
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31