Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
87 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65807 | Microsoft Excel Remote Code Execution Vulnerability | Important | 13 Elevated | 8.8 | 0.004 | No | No | Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more |
| CVE-2026-70130 | Microsoft Office Remote Code Execution Vulnerability | Critical | 13 Elevated | 8.4 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more |
| CVE-2026-63513 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63515 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +7 more |
| CVE-2026-63518 | Microsoft Office Word Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63519 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +5 more |
| CVE-2026-63525 | Microsoft Office Word Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-63526 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +7 more |
| CVE-2026-63527 | Microsoft Office Word Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63532 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63533 | Microsoft Office Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +7 more |
| CVE-2026-64898 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +5 more |
| CVE-2026-64903 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64905 | Microsoft Office Word Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64906 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64907 | Microsoft Office Word Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64908 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64909 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +7 more |
| CVE-2026-64910 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more |
| CVE-2026-64911 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more |
| CVE-2026-64912 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64914 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64915 | Microsoft Office Word Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64920 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-65656 | Microsoft Office Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more |
The CSV is exactly the 87 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-65807 — Microsoft Excel Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 8.8
FIRST EPSS: 0.004 (36.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002884, 5002903
Affected product(s): Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more
CVE-2026-70130 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.4, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 8.4
FIRST EPSS: 0.003 (24.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more
CVE-2026-63513 — Microsoft Office Graphics Component Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63515 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002902
Affected product(s): Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +7 more
CVE-2026-63518 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002755
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63519 — Microsoft Office Graphics Component Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +5 more
CVE-2026-63525 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (30.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-63526 — Microsoft Office Graphics Component Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +7 more
CVE-2026-63527 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63532 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63533 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +7 more
CVE-2026-64898 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +5 more
CVE-2026-64903 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64905 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64906 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64907 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64908 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64909 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +7 more
CVE-2026-64910 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-64911 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-64912 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64914 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (33.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002813
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64915 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64920 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-65656 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more