« Volver al listado

Microsoft

Microsoft Office Online Server: vulnerabilidades y CVE

Microsoft Office Online Server tiene 237 vulnerabilidades publicadas, 86 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE237
Últimos 12 meses86
Críticas2
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2017-11826Alta (7.8)81%⚠ Explotación activa13 oct 2017
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81956Alta (7.8)0.47%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81947Alta (7.8)0.47%—8 sept 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81401Media (5.5)0.54%—8 sept 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81390Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55949Alta (7.8)0.47%—14 jul 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55947Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55898Alta (7.1)0.47%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55141Alta (7.8)0.47%—14 jul 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55138Media (5.5)0.54%—14 jul 2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55137Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55136Alta (7.8)0.47%—14 jul 2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55131Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55128Alta (7.8)0.57%—14 jul 2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55127Alta (7.8)0.57%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55124Media (5.5)0.60%—14 jul 2026
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55122Alta (7.1)0.53%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55058Alta (7.8)0.47%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55054Media (6.5)0.92%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-55053Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55050Media (5.5)0.60%—14 jul 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55048Alta (7.8)0.47%—14 jul 2026
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55047Media (5.5)0.60%—14 jul 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55046Media (5.5)0.54%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55044Alta (7.8)0.47%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55041Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55039Alta (7.8)0.47%—14 jul 2026
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55037Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55036Alta (7.8)0.47%—14 jul 2026
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55031Alta (7.8)0.47%—14 jul 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55029Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution2
  2. T1204.002 Malicious File2
  3. T1499.004 Application or System Exploitation2
  4. T1574 Hijack Execution Flow2
  5. T1059 Command and Scripting Interpreter1
  6. T1566 Phishing1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft