« Volver al listado

Microsoft

Microsoft 365 Apps: vulnerabilidades y CVE

Microsoft 365 Apps tiene 771 vulnerabilidades publicadas, 390 de ellas en los últimos 12 meses. 6 son críticas y 10 figuran en el catálogo de explotación activa de CISA.

CVE771
Últimos 12 meses390
Críticas6
Explotadas activamente10

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21514Alta (7.8)1.6%⚠ Explotación activa10 feb 2026
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-21509Alta (7.8)71%⚠ Explotación activa26 ene 2026
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2024-21413Crítica (9.8)95%⚠ Explotación activa13 feb 2024
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-38189Alta (8.8)8.2%⚠ Explotación activa13 ago 2024
Microsoft Project Remote Code Execution Vulnerability
CVE-2023-36761Media (6.5)20%⚠ Explotación activa12 sept 2023
Microsoft Word Information Disclosure Vulnerability
CVE-2023-35311Alta (7.5)16%⚠ Explotación activa11 jul 2023
Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2023-23397Crítica (9.8)97%⚠ Explotación activa14 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2023-21715Alta (7.3)12%⚠ Explotación activa14 feb 2023
Microsoft Publisher Security Feature Bypass Vulnerability
CVE-2021-38646Alta (7.8)8.0%⚠ Explotación activa15 sept 2021
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-42292Alta (7.8)43%⚠ Explotación activa10 nov 2021
Microsoft Excel Security Feature Bypass Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85875Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-83951Media (5.5)0.54%—8 sept 2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-83949Media (5.5)0.54%—8 sept 2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-81960Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81959Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81958Media (5.5)0.54%—8 sept 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81957Alta (7.8)0.47%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81956Alta (7.8)0.47%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81954Alta (7.8)0.47%—8 sept 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81953Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81952Alta (8.8)0.82%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-81951Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81950Alta (7.8)0.47%—8 sept 2026
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81949Alta (7.8)0.47%—8 sept 2026
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81948Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81947Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81401Media (5.5)0.54%—8 sept 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81400Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81399Media (5.5)0.54%—8 sept 2026
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81398Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81397Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81396Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81395Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81394Media (5.5)0.55%—8 sept 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81393Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81392Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81391Media (5.5)0.54%—8 sept 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81390Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81389Alta (7)0.37%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81388Alta (7.8)0.47%—8 sept 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter4
  2. T1068 Exploitation for Privilege Escalation4
  3. T1203 Exploitation for Client Execution4
  4. T1059.007 JavaScript2
  5. T1190 Exploit Public-Facing Application2
  6. T1204.002 Malicious File2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft