# Multiple Microsoft Office vulnerabilities enable remote code execution

Published: 2026-07-15 · Severity: routine
Canonical: https://vorant.io/reports/8776d591-ccb4-545a-8c34-1a4c5735e758/multiple-microsoft-office-vulnerabilities-enable-remote-code-execution

> ANSSI advisory covers 72 CVEs across Microsoft Office 2016, 2019, LTSC editions, and cloud apps allowing remote code execution, privilege escalation, and data theft.

ANSSI has published a security advisory covering a large batch of vulnerabilities affecting Microsoft Office products across multiple versions and platforms. The vulnerabilities span Microsoft Office 2016 (32/64-bit), Office 2019, Office LTSC 2021 and 2024 editions, Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft 365 Copilot for mobile platforms, and Office Online Server. The advisory indicates three primary impact categories: remote code execution, privilege escalation, and confidentiality breaches. Affected versions include Office 2016 prior to 16.0.5561.1000/1001 across Word, Excel, and PowerPoint; Office 2019 in all editions; LTSC versions for both 2021 and 2024; Office 365 for Mac prior to 16.111.26071215; Office for Android prior to 16.0.20228.20042; and Microsoft 365 Copilot for iOS prior to 2.111.4. Defenders should prioritize patching these products across their estate, with particular attention to widely-deployed Office 2016 and cloud-connected Microsoft 365 deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-47290, CVE-2026-47642, CVE-2026-48561, CVE-2026-48580, CVE-2026-50301, CVE-2026-50314, CVE-2026-50387, CVE-2026-50408, CVE-2026-50467, CVE-2026-50665, CVE-2026-50675, CVE-2026-50678, CVE-2026-54131, CVE-2026-54988, CVE-2026-55017, CVE-2026-55018, CVE-2026-55022, CVE-2026-55023, CVE-2026-55024, CVE-2026-55025, CVE-2026-55026, CVE-2026-55027, CVE-2026-55028, CVE-2026-55029, CVE-2026-55031, CVE-2026-55032, CVE-2026-55033, CVE-2026-55035, CVE-2026-55036, CVE-2026-55037, CVE-2026-55038, CVE-2026-55039, CVE-2026-55041, CVE-2026-55042, CVE-2026-55043, CVE-2026-55044, CVE-2026-55045, CVE-2026-55046, CVE-2026-55047, CVE-2026-55048

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0868

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8776d591-ccb4-545a-8c34-1a4c5735e758/multiple-microsoft-office-vulnerabilities-enable-remote-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
