Microsoft Patch Tuesday

This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.

Browse This Release's CVEs

Severity
Exploitation

56 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.

CVEs in this Patch Tuesday release matching the current filters, ranked by EVULNABLE Risk Score
CVE TitleMSRC severity EVRS CVSS EPSS KEV Actively Exploited Product(s)
CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability Critical 13 Elevated 8.4 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more
CVE-2026-58651 Microsoft Word Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.004 No No Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +3 more
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.004 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.004 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63525 Microsoft Office Word Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.004 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-63527 Microsoft Office Word Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63532 Microsoft Office Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-63533 Microsoft Office Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +7 more
CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64905 Microsoft Office Word Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64907 Microsoft Office Word Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64908 Microsoft Access Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64910 Microsoft Office Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-64911 Microsoft Office Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-64912 Microsoft Access Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64914 Microsoft Access Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.004 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-64915 Microsoft Office Word Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-64920 Microsoft Access Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.003 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
CVE-2026-65656 Microsoft Office Remote Code Execution Vulnerability Important 12 Elevated 7.8 0.004 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more
CVE-2026-65657 Microsoft Office Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.004 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-65664 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.004 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 12 Elevated 7.8 0.004 No No Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft Office LTSC 2024 for 32-bit editions, +5 more
CVE-2026-68792 Microsoft Office Elevation of Privilege Vulnerability Important 12 Elevated 7.8 0.002 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more
CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability Important 11 Elevated 8.8 0.007 No No Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more
Download filtered CVEs (CSV) Patch Tuesday Brief (PDF)

The CSV is exactly the 56 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.

CVE detail

Expand any CVE for its description, EVRS score breakdown, and affected products.

CVE-2026-70130 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.4, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.4

FIRST EPSS: 0.003 (24.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more

CVE-2026-58651 — Microsoft Word Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (33.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +3 more

CVE-2026-63513 — Microsoft Office Graphics Component Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002897

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-63518 — Microsoft Office Word Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002755

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-63525 — Microsoft Office Word Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (30.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002901

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more

CVE-2026-63527 — Microsoft Office Word Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002901

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-63532 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002897

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-63533 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002897

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +7 more

CVE-2026-64903 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002897

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-64905 — Microsoft Office Word Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002901

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-64906 — Microsoft Access Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002832

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more

CVE-2026-64907 — Microsoft Office Word Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002901

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-64908 — Microsoft Access Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002832

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more

CVE-2026-64910 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more

CVE-2026-64911 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (26.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more

CVE-2026-64912 — Microsoft Access Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002832

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more

CVE-2026-64914 — Microsoft Access Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (33.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002813

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more

CVE-2026-64915 — Microsoft Office Word Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002901

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more

CVE-2026-64920 — Microsoft Access Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (22.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002832

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more

CVE-2026-65656 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (28.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more

CVE-2026-65657 — Microsoft Office Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (36.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more

CVE-2026-65664 — Microsoft Office Graphics Component Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +5 more

CVE-2026-66807 — Microsoft Office Graphics Component Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft Office LTSC 2024 for 32-bit editions, +5 more

CVE-2026-68792 — Microsoft Office Elevation of Privilege Vulnerability

Elevation of Privilege

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.002 (16.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +2 more

CVE-2026-70329 — Microsoft Outlook Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 11/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Unlikely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Unlikely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.007 (49.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002755

Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.