VORANT. Threat Intelligence Sign in Get the full feed

Multiple Microsoft Office vulnerabilities enable remote code execution

routine vulnerability

ANSSI advisory covers 72 CVEs across Microsoft Office 2016, 2019, LTSC editions, and cloud apps allowing remote code execution, privilege escalation, and data theft.

ANSSI has published a security advisory covering a large batch of vulnerabilities affecting Microsoft Office products across multiple versions and platforms. The vulnerabilities span Microsoft Office 2016 (32/64-bit), Office 2019, Office LTSC 2021 and 2024 editions, Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft 365 Copilot for mobile platforms, and Office Online Server. The advisory indicates three primary impact categories: remote code execution, privilege escalation, and confidentiality breaches. Affected versions include Office 2016 prior to 16.0.5561.1000/1001 across Word, Excel, and PowerPoint; Office 2019 in all editions; LTSC versions for both 2021 and 2024; Office 365 for Mac prior to 16.111.26071215; Office for Android prior to 16.0.20228.20042; and Microsoft 365 Copilot for iOS prior to 2.111.4. Defenders should prioritize patching these products across their estate, with particular attention to widely-deployed Office 2016 and cloud-connected Microsoft 365 deployments.

Mentioned in this report

Vulnerabilities CVE-2026-47290CVE-2026-47642CVE-2026-48561CVE-2026-48580CVE-2026-50301CVE-2026-50314CVE-2026-50387CVE-2026-50408CVE-2026-50467CVE-2026-50665CVE-2026-50675CVE-2026-50678CVE-2026-54131CVE-2026-54988CVE-2026-55017CVE-2026-55018CVE-2026-55022CVE-2026-55023CVE-2026-55024CVE-2026-55025CVE-2026-55026CVE-2026-55027CVE-2026-55028CVE-2026-55029CVE-2026-55031CVE-2026-55032CVE-2026-55033CVE-2026-55035CVE-2026-55036CVE-2026-55037CVE-2026-55038CVE-2026-55039CVE-2026-55041CVE-2026-55042CVE-2026-55043CVE-2026-55044CVE-2026-55045CVE-2026-55046CVE-2026-55047CVE-2026-55048

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0868

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free