Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
56 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-70130 | Microsoft Office Remote Code Execution Vulnerability | Critical | 13 Elevated | 8.4 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more |
| CVE-2026-58651 | Microsoft Word Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +3 more |
| CVE-2026-63513 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63518 | Microsoft Office Word Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63525 | Microsoft Office Word Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-63527 | Microsoft Office Word Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63532 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-63533 | Microsoft Office Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +7 more |
| CVE-2026-64903 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64905 | Microsoft Office Word Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64906 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64907 | Microsoft Office Word Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64908 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64910 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more |
| CVE-2026-64911 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more |
| CVE-2026-64912 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64914 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-64915 | Microsoft Office Word Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-64920 | Microsoft Access Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
| CVE-2026-65656 | Microsoft Office Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more |
| CVE-2026-65657 | Microsoft Office Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more |
| CVE-2026-65664 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more |
| CVE-2026-66807 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical | 12 Elevated | 7.8 | 0.004 | No | No | Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft Office LTSC 2024 for 32-bit editions, +5 more |
| CVE-2026-68792 | Microsoft Office Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.002 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more |
| CVE-2026-70329 | Microsoft Outlook Remote Code Execution Vulnerability | Important | 11 Elevated | 8.8 | 0.007 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
The CSV is exactly the 56 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-70130 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.4, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 8.4
FIRST EPSS: 0.003 (24.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more
CVE-2026-58651 — Microsoft Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (33.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +3 more
CVE-2026-63513 — Microsoft Office Graphics Component Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63518 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002755
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63525 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (30.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-63527 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63532 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63533 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +7 more
CVE-2026-64903 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002897
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64905 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64906 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64907 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64908 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64910 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-64911 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-64912 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64914 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (33.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002813
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64915 — Microsoft Office Word Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64920 — Microsoft Access Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002832
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-65656 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more
CVE-2026-65657 — Microsoft Office Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (36.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-65664 — Microsoft Office Graphics Component Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-66807 — Microsoft Office Graphics Component Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft Office LTSC 2024 for 32-bit editions, +5 more
CVE-2026-68792 — Microsoft Office Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.002 (16.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more
CVE-2026-70329 — Microsoft Outlook Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 8.8
FIRST EPSS: 0.007 (49.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002755
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more