Multiples vulnérabilités dans Microsoft Office (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Office. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1145/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-729380.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-779010.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813950.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-729770.99% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-697220.82% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-649180.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-696860.82% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-785040.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-800820.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-813851.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Microsoft Office Produkte: Mehrere Schwachstellencert-bund
- unknownNCSC-2026-0352 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Officencsc-nl
- mediumCVE-2026-83951: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose informat…nvd
- mediumCVE-2026-83949: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose informat…nvd
- highCVE-2026-81959: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execut…nvd
- highCVE-2026-81957: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code l…nvd
- highCVE-2026-81954: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code local…nvd
- highCVE-2026-81952: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute…nvd
- highCVE-2026-81948: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execut…nvd
- mediumCVE-2026-81401: Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows…nvd
- mediumCVE-2026-81400: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose infor…nvd
- highCVE-2026-81396: Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execu…nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans Microsoft Azure (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans Google Chrome (09 septembre 2026)2026-09-09
- unknownVulnérabilité dans les produits Cisco (09 septembre 2026)2026-09-09
- unknownVulnérabilité dans les produits ESET (09 septembre 2026)2026-09-09