Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Microsoft Office LTSC for Mac 2024.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-68817HIGH | Microsoft Excel Remote Code Execution VulnerabilityStack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. CWE-121Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.404% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68814HIGH | Microsoft Excel Remote Code Execution VulnerabilityOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. CWE-125Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.404% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68812HIGH | Microsoft Excel Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.404% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68805HIGH | Microsoft Excel Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.325% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68804HIGH | Microsoft Excel Remote Code Execution VulnerabilityNumeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68803HIGH | Microsoft Excel Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. CWE-843Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.303% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68801HIGH | Microsoft Excel Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.325% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68799MEDIUM | Microsoft Excel Information Disclosure VulnerabilityUse of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. CWE-908Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.345% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68798HIGH | Microsoft Excel Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.421% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68797MEDIUM | Microsoft Excel Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.447% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66809MEDIUM | Microsoft Office Graphics Component Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66810MEDIUM | Microsoft Office Word Information Disclosure VulnerabilityHeap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. CWE-122Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66807HIGH | Microsoft Office Graphics Component Remote Code Execution VulnerabilityStack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-121Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.359% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64917MEDIUM | Microsoft Office Word Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64915HIGH | Microsoft Office Word Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64911HIGH | Microsoft Office Remote Code Execution VulnerabilityInteger overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.348% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64910HIGH | Microsoft Office Remote Code Execution VulnerabilityUntrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-822Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.348% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64909HIGH | Microsoft Office Remote Code Execution VulnerabilityInteger underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.348% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64907HIGH | Microsoft Office Word Remote Code Execution VulnerabilityStack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. CWE-121Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.348% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64905HIGH | Microsoft Office Word Remote Code Execution VulnerabilityBuffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. CWE-126Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64904HIGH | Microsoft Office Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-843Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64903HIGH | Microsoft Office Remote Code Execution VulnerabilityInteger overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.348% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64899MEDIUM | Microsoft Office Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64898HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.348% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-63533HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |