Microsoft
Microsoft Excel: vulnerabilidades y CVE
Microsoft Excel tiene 505 vulnerabilidades publicadas, 141 de ellas en los últimos 12 meses. 2 son críticas y 6 figuran en el catálogo de explotación activa de CISA.
CVE505
Últimos 12 meses141
Críticas2
Explotadas activamente6
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2009-0238 | Alta (8.8) | 43% | ⚠ Explotación activa | 25 feb 2009 | Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office… |
| CVE-2007-0671 | Alta (8.8) | 43% | ⚠ Explotación activa | 3 feb 2007 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as… |
| CVE-2019-1297 | Alta (8.8) | 22% | ⚠ Explotación activa | 11 sept 2019 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. |
| CVE-2009-3129 | Alta (7.8) | 84% | ⚠ Explotación activa | 11 nov 2009 | Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office… |
| CVE-2016-7262 | Alta (7.8) | 58% | ⚠ Explotación activa | 20 dic 2016 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted… |
| CVE-2021-42292 | Alta (7.8) | 43% | ⚠ Explotación activa | 10 nov 2021 | Microsoft Excel Security Feature Bypass Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85875 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81960 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81959 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81958 | Media (5.5) | 0.54% | — | 8 sept 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81957 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81956 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81954 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81953 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81951 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81950 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81949 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81948 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81947 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81401 | Media (5.5) | 0.54% | — | 8 sept 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81400 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81399 | Media (5.5) | 0.54% | — | 8 sept 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81398 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81397 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81396 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81395 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81394 | Media (5.5) | 0.55% | — | 8 sept 2026 | Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81393 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81392 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81391 | Media (5.5) | 0.54% | — | 8 sept 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81390 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81389 | Alta (7) | 0.37% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81388 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81387 | Media (5.5) | 0.55% | — | 8 sept 2026 | Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81386 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-78518 | Alta (8.8) | 0.86% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.