« Back to list

Microsoft

Microsoft Office 2016: vulnerabilities and CVEs

Microsoft Office 2016 has 108 published vulnerabilities, 104 of them in the last 12 months. 1 are rated critical and 4 are listed by CISA as actively exploited.

CVEs108
Last 12 months104
Critical1
Actively exploited4

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-21413Critical (9.8)95%⚠ Active exploitationFeb 13, 2024
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2021-38646High (7.8)8.0%⚠ Active exploitationSep 15, 2021
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-42292High (7.8)43%⚠ Active exploitationNov 10, 2021
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2021-27059Medium (6.5)6.1%⚠ Active exploitationMar 11, 2021
Microsoft Office Remote Code Execution Vulnerability

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-85875Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81960High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81959High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81958Medium (5.5)0.54%—Sep 8, 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81957High (7.8)0.47%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81956High (7.8)0.47%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81954High (7.8)0.47%—Sep 8, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81953High (7.8)0.47%—Sep 8, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81952High (8.8)0.82%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-81951High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81950High (7.8)0.47%—Sep 8, 2026
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81949High (7.8)0.47%—Sep 8, 2026
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81948High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81947High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81401Medium (5.5)0.54%—Sep 8, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81400Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81399Medium (5.5)0.54%—Sep 8, 2026
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81398High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81397High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81396High (7.8)0.47%—Sep 8, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81395Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81394Medium (5.5)0.55%—Sep 8, 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81393Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81392Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81391Medium (5.5)0.54%—Sep 8, 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81390Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81389High (7)0.37%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81388High (7.8)0.47%—Sep 8, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81387Medium (5.5)0.55%—Sep 8, 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81386High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter2
  2. T1068 Exploitation for Privilege Escalation2
  3. T1059.005 Visual Basic1
  4. T1059.007 JavaScript1
  5. T1190 Exploit Public-Facing Application1
  6. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft