Microsoft
Microsoft Office Online Server: vulnerabilidades y CVE
Microsoft Office Online Server tiene 237 vulnerabilidades publicadas, 86 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE237
Últimos 12 meses86
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-11826 | Alta (7.8) | 81% | ⚠ Explotación activa | 13 oct 2017 | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81956 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81947 | Alta (7.8) | 0.47% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-81401 | Media (5.5) | 0.54% | — | 8 sept 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-81390 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55949 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55947 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55898 | Alta (7.1) | 0.47% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55141 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55138 | Media (5.5) | 0.54% | — | 14 jul 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55137 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55136 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55131 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55128 | Alta (7.8) | 0.57% | — | 14 jul 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-55127 | Alta (7.8) | 0.57% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-55124 | Media (5.5) | 0.60% | — | 14 jul 2026 | Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55122 | Alta (7.1) | 0.53% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55058 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55054 | Media (6.5) | 0.92% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-55053 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55050 | Media (5.5) | 0.60% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55048 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55047 | Media (5.5) | 0.60% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55046 | Media (5.5) | 0.54% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55044 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55041 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55039 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55037 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55036 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55031 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-55029 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.