365 Apps Microsoft 365 Apps

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft 365 Apps.

By the Year

In 2026 there have been 353 vulnerabilities in Microsoft 365 Apps with an average score of 7.3 out of ten. Last year, in 2025 365 Apps had 154 security vulnerabilities published. That is, 199 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.42




Year Vulnerabilities Average Score
2026 353 7.28
2025 154 7.70
2024 42 7.69
2023 56 7.44
2022 46 7.26
2021 64 7.45
2020 54 7.25

It may take a day or so for new 365 Apps vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft 365 Apps Security Vulnerabilities

Sep 2026: Microsoft Word Remote Code Execution Vulnerability
CVE-2026-62804 7.8 - High - September 08, 2026

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

External Control of File Name or Path

Sep 2026: Microsoft Office Excel Information Disclosure Vulnerability
CVE-2026-85875 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Office Word Information Disclosure Vulnerability
CVE-2026-83951 5.5 - Medium - September 08, 2026

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Buffer Over-read

Sep 2026: Microsoft Office Word Information Disclosure Vulnerability
CVE-2026-83949 5.5 - Medium - September 08, 2026

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Buffer Over-read

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81950 7.8 - High - September 08, 2026

Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Double-free

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81948 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81949 7.8 - High - September 08, 2026

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Integer Overflow or Wraparound

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81959 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81953 7.8 - High - September 08, 2026

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack Overflow

Sep 2026: Microsoft Word Remote Code Execution Vulnerability
CVE-2026-81952 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81951 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81388 7.8 - High - September 08, 2026

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack Overflow

Sep 2026: Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-81955 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81957 7.8 - High - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Out-of-bounds Read

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81960 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81395 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81389 7 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81394 5.5 - Medium - September 08, 2026

Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81400 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81393 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81956 7.8 - High - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Out-of-bounds Read

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81397 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81392 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81396 7.8 - High - September 08, 2026

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack Overflow

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81958 5.5 - Medium - September 08, 2026

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Use of Uninitialized Resource

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81391 5.5 - Medium - September 08, 2026

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Use of Uninitialized Resource

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81401 5.5 - Medium - September 08, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Object Type Confusion

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81399 5.5 - Medium - September 08, 2026

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Buffer Over-read

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81390 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81954 7.8 - High - September 08, 2026

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dangling pointer

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81947 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Information Disclosure Vulnerability
CVE-2026-81387 5.5 - Medium - September 08, 2026

Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81398 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-81386 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Office Publisher Remote Code Execution Vulnerability
CVE-2026-81385 8.8 - High - September 08, 2026

Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

Marshaling, Unmarshaling

Sep 2026: Microsoft Office PowerPoint Remote Code Execution Vulnerability
CVE-2026-80081 8.8 - High - September 08, 2026

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Microsoft Office Information Disclosure Vulnerability
CVE-2026-80082 6.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft Office Word Information Disclosure Vulnerability
CVE-2026-80090 6.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft Office Information Disclosure Vulnerability
CVE-2026-80091 6.5 - Medium - September 08, 2026

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Use of Uninitialized Resource

Sep 2026: Microsoft Office Information Disclosure Vulnerability
CVE-2026-80089 6.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft Office Word Information Disclosure Vulnerability
CVE-2026-80088 6.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-80085 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft Office Information Disclosure Vulnerability
CVE-2026-80087 6.5 - Medium - September 08, 2026

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-80080 8.8 - High - September 08, 2026

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Double-free

Sep 2026: Microsoft Office PowerPoint Information Disclosure Vulnerability
CVE-2026-80086 6.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft Office Outlook Remote Code Execution Vulnerability
CVE-2026-78525 8.8 - High - September 08, 2026

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Microsoft Office Outlook Information Disclosure Vulnerability
CVE-2026-80084 6.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft Office Information Disclosure Vulnerability
CVE-2026-80076 6.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-78526 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft Office Remote Code Execution Vulnerability
CVE-2026-78524 8.8 - High - September 08, 2026

Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft 365 Apps or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe