Microsoft
Microsoft Office 2016: vulnerabilities and CVEs
Microsoft Office 2016 has 108 published vulnerabilities, 104 of them in the last 12 months. 1 are rated critical and 4 are listed by CISA as actively exploited.
CVEs108
Last 12 months104
Critical1
Actively exploited4
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21413 | Critical (9.8) | 95% | ⚠ Active exploitation | Feb 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2021-38646 | High (7.8) | 8.0% | ⚠ Active exploitation | Sep 15, 2021 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
| CVE-2021-42292 | High (7.8) | 43% | ⚠ Active exploitation | Nov 10, 2021 | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2021-27059 | Medium (6.5) | 6.1% | ⚠ Active exploitation | Mar 11, 2021 | Microsoft Office Remote Code Execution Vulnerability |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85875 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81960 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81959 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81958 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81957 | High (7.8) | 0.47% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81956 | High (7.8) | 0.47% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81954 | High (7.8) | 0.47% | — | Sep 8, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81953 | High (7.8) | 0.47% | — | Sep 8, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81952 | High (8.8) | 0.82% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
| CVE-2026-81951 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81950 | High (7.8) | 0.47% | — | Sep 8, 2026 | Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81949 | High (7.8) | 0.47% | — | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81948 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81947 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81401 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81400 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81399 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81398 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81397 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81396 | High (7.8) | 0.47% | — | Sep 8, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81395 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81394 | Medium (5.5) | 0.55% | — | Sep 8, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81393 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81392 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81391 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81390 | Medium (5.5) | 0.54% | — | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81389 | High (7) | 0.37% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81388 | High (7.8) | 0.47% | — | Sep 8, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81387 | Medium (5.5) | 0.55% | — | Sep 8, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81386 | High (7.8) | 0.47% | — | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.