# Microsoft Office Patch Batch: 130+ CVEs

Published: 2026-09-09 · Severity: routine
Canonical: https://vorant.io/reports/1fe3fa04-7a2d-57a3-8114-7783e3749e3c/microsoft-office-patch-batch-130-cves

> ANSSI advisory details over 130 Microsoft Office vulnerabilities enabling remote code execution, data disclosure, and security bypass; patch immediately.

ANSSI (the French national cybersecurity agency) published a security advisory (CERTFR-2026-AVI-1145) consolidating a large batch of Microsoft Office vulnerabilities disclosed in Microsoft's September 2026 security bulletins. The affected product set is broad, spanning Microsoft 365 Apps for Enterprise (32-bit and 64-bit), Office 2016, Office 2019, Office LTSC 2021/2024 (Windows and Mac), Office for Android, Office Online Server, and individual applications including Word, Excel, PowerPoint, Outlook, Access, and Publisher. Over 130 distinct CVEs are referenced, though ANSSI's summary does not provide individual technical descriptions for each — it groups them under three risk categories: remote code execution, confidentiality breach (data disclosure), and security policy bypass.

No evidence of active in-the-wild exploitation is mentioned in this bulletin; it is a standard vendor-patch consolidation advisory. Given the sheer volume of RCE-capable flaws across nearly every supported Office version and platform, organizations should prioritize deployment of the referenced Microsoft updates across all affected product lines. Defenders should treat document-based attack surfaces (macro execution, OLE embedding, file parsing) as the likely vector class for these flaws and ensure patch management processes cover both mainstream Office channels and legacy/LTSC editions, which are frequently overlooked in update cycles.

As is typical for ANSSI Office bulletins, remediation guidance is simply to apply the vendor patches referenced in the Microsoft Security Response Center (MSRC) update guide entries for each CVE. No IOCs, threat actor attribution, or malware association is provided in the source material, consistent with a routine vulnerability disclosure rather than an incident report.

## Mentioned in this report

- Vulnerabilities: CVE-2026-62804, CVE-2026-64918, CVE-2026-69285, CVE-2026-69442, CVE-2026-69477, CVE-2026-69529, CVE-2026-69556, CVE-2026-69614, CVE-2026-69626, CVE-2026-69629, CVE-2026-69632, CVE-2026-69671, CVE-2026-69678, CVE-2026-69686, CVE-2026-69719, CVE-2026-69722, CVE-2026-69734, CVE-2026-69739, CVE-2026-69742, CVE-2026-69759, CVE-2026-69764, CVE-2026-69767, CVE-2026-69778, CVE-2026-69797, CVE-2026-72938, CVE-2026-72956, CVE-2026-72972, CVE-2026-72973, CVE-2026-72974, CVE-2026-72975, CVE-2026-72976, CVE-2026-72977, CVE-2026-77898, CVE-2026-77901, CVE-2026-77911, CVE-2026-78439, CVE-2026-78502, CVE-2026-78503, CVE-2026-78504, CVE-2026-78505

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1145

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1fe3fa04-7a2d-57a3-8114-7783e3749e3c/microsoft-office-patch-batch-130-cves.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
