CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0286 [1.00] [M/H] Vulnerabilities patched in Microsoft Office

unknownCVE-2026-65667CVE-2026-50515CVE-2026-62896CVE-2026-70332CVE-2026-70306CVE-2026-65680
Microsoft has patched vulnerabilities in various Office products. An attacker can exploit the vulnerabilities to conduct attacks that may result in the damage categories described in the table below. Successful exploitation requires the attacker to trick the victim into opening a malicious file or following a link. The table below mentions the vulnerability with identifier CVE-2026-65667 with a CVSS score of 10.0. It also lists vulnerabilities with identifiers CVE-2026-50515, CVE-2026-62896 and CVE-2026-70332, each with a CVSS score of 9 or higher. However, these vulnerabilities have already been centrally patched by Microsoft and are included for informational purposes only. No action is required for these. The vulnerability with identifier CVE-2026-70306 also has a CVSS score higher than 9 and does require action. This vulnerability is located in Sharepoint and allows an attacker to execute arbitrary code in the victim's context through a cross-site scripting attack. Microsoft OneDrive: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65680 | 6.70 | Privilege escalation | |----------------|------|-------------------------------------| Azure SQL Managed Instance: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-62836 | 8.70 | Privilege escalation | |----------------|------|-------------------------------------| Microsoft Teams for Android: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65768 | 8.80 | Arbitrary code execution | | CVE-2026-65767 | 8.80 | Impersonation of other users | |----------------|------|-

CSIRTS triage

What
Multiple vulnerabilities in Office products allow remote code execution and information disclosure; CVE-2026-70306 in SharePoint requires action.
Who is affected
Microsoft Office users and SharePoint deployments are affected; exploitation requires user interaction.
Urgency
High—CVE-2026-70306 (CVSS 9+) in SharePoint requires action and has not been pre-patched centrally.
Action
Prioritize patching of CVE-2026-70306 in SharePoint; verify status of other Office vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Office and SharePoint

Get an email when a new Office and SharePoint advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0286

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-65667coverage & exploitation statusNVD · CVE.org
CVE-2026-50515coverage & exploitation statusNVD · CVE.org
CVE-2026-62896coverage & exploitation statusNVD · CVE.org
CVE-2026-70332coverage & exploitation statusNVD · CVE.org
CVE-2026-70306coverage & exploitation statusNVD · CVE.org
CVE-2026-65680coverage & exploitation statusNVD · CVE.org
CVE-2026-62836coverage & exploitation statusNVD · CVE.org
CVE-2026-65768coverage & exploitation statusNVD · CVE.org
CVE-2026-65767coverage & exploitation statusNVD · CVE.org
CVE-2026-62918coverage & exploitation statusNVD · CVE.org
CVE-2026-63518coverage & exploitation statusNVD · CVE.org
CVE-2026-63521coverage & exploitation statusNVD · CVE.org
CVE-2026-70311coverage & exploitation statusNVD · CVE.org
CVE-2026-70310coverage & exploitation statusNVD · CVE.org
CVE-2026-70319coverage & exploitation statusNVD · CVE.org
CVE-2026-58651coverage & exploitation statusNVD · CVE.org
CVE-2026-63525coverage & exploitation statusNVD · CVE.org
CVE-2026-63528coverage & exploitation statusNVD · CVE.org
CVE-2026-63527coverage & exploitation statusNVD · CVE.org
CVE-2026-63530coverage & exploitation statusNVD · CVE.org
CVE-2026-63531coverage & exploitation statusNVD · CVE.org
CVE-2026-64905coverage & exploitation statusNVD · CVE.org
CVE-2026-64907coverage & exploitation statusNVD · CVE.org
CVE-2026-64915coverage & exploitation statusNVD · CVE.org
CVE-2026-64917coverage & exploitation statusNVD · CVE.org
CVE-2026-66806coverage & exploitation statusNVD · CVE.org
CVE-2026-66810coverage & exploitation statusNVD · CVE.org
CVE-2026-63513coverage & exploitation statusNVD · CVE.org
CVE-2026-63515coverage & exploitation statusNVD · CVE.org
CVE-2026-63517coverage & exploitation statusNVD · CVE.org
CVE-2026-63519coverage & exploitation statusNVD · CVE.org
CVE-2026-65657coverage & exploitation statusNVD · CVE.org
CVE-2026-65656coverage & exploitation statusNVD · CVE.org
CVE-2026-65661coverage & exploitation statusNVD · CVE.org
CVE-2026-65664coverage & exploitation statusNVD · CVE.org
CVE-2026-68792coverage & exploitation statusNVD · CVE.org
CVE-2026-70315coverage & exploitation statusNVD · CVE.org
CVE-2026-70314coverage & exploitation statusNVD · CVE.org
CVE-2026-70317coverage & exploitation statusNVD · CVE.org
CVE-2026-70323coverage & exploitation statusNVD · CVE.org
CVE-2026-62842coverage & exploitation statusNVD · CVE.org
CVE-2026-63524coverage & exploitation statusNVD · CVE.org
CVE-2026-63526coverage & exploitation statusNVD · CVE.org
CVE-2026-63529coverage & exploitation statusNVD · CVE.org
CVE-2026-63532coverage & exploitation statusNVD · CVE.org
CVE-2026-63533coverage & exploitation statusNVD · CVE.org
CVE-2026-64898coverage & exploitation statusNVD · CVE.org
CVE-2026-64899coverage & exploitation statusNVD · CVE.org

+80 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Microsoft Office

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories