Microsoft
Microsoft 365 Apps: vulnerabilidades y CVE
Microsoft 365 Apps tiene 771 vulnerabilidades publicadas, 390 de ellas en los últimos 12 meses. 6 son críticas y 10 figuran en el catálogo de explotación activa de CISA.
CVE771
Últimos 12 meses390
Críticas6
Explotadas activamente10
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21514 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 10 feb 2026 | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-21509 | Alta (7.8) | 71% | ⚠ Explotación activa | 26 ene 2026 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2024-21413 | Crítica (9.8) | 95% | ⚠ Explotación activa | 13 feb 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-38189 | Alta (8.8) | 8.2% | ⚠ Explotación activa | 13 ago 2024 | Microsoft Project Remote Code Execution Vulnerability |
| CVE-2023-36761 | Media (6.5) | 20% | ⚠ Explotación activa | 12 sept 2023 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2023-35311 | Alta (7.5) | 16% | ⚠ Explotación activa | 11 jul 2023 | Microsoft Outlook Security Feature Bypass Vulnerability |
| CVE-2023-23397 | Crítica (9.8) | 97% | ⚠ Explotación activa | 14 mar 2023 | Microsoft Outlook Elevation of Privilege Vulnerability |
| CVE-2023-21715 | Alta (7.3) | 12% | ⚠ Explotación activa | 14 feb 2023 | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2021-38646 | Alta (7.8) | 8.0% | ⚠ Explotación activa | 15 sept 2021 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
| CVE-2021-42292 | Alta (7.8) | 43% | ⚠ Explotación activa | 10 nov 2021 | Microsoft Excel Security Feature Bypass Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85875 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-83951 | Media (5.5) | 0.54% | — | 8 sept 2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-83949 | Media (5.5) | 0.54% | — | 8 sept 2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81960 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81959 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81958 | Media (5.5) | 0.54% | — | 8 sept 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81957 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81956 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81954 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81953 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81952 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| CVE-2026-81951 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81950 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81949 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81948 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81947 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81401 | Media (5.5) | 0.54% | — | 8 sept 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81400 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81399 | Media (5.5) | 0.54% | — | 8 sept 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81398 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81397 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81396 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81395 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81394 | Media (5.5) | 0.55% | — | 8 sept 2026 | Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81393 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81392 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81391 | Media (5.5) | 0.54% | — | 8 sept 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81390 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81389 | Alta (7) | 0.37% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81388 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.