VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR Flags Mass Microsoft Office CVE Batch

routine vulnerability

CERT-FR advisory lists over 100 Microsoft Office vulnerabilities patched in the August 2026 update covering RCE, privilege escalation, and data exposure.

CERT-FR published a routine security advisory summarizing a large batch of vulnerabilities affecting multiple Microsoft Office products, including Office 2016, 2019, LTSC 2021/2024, Access, Excel, Outlook, PowerPoint, Word, and Microsoft 365 Apps for Enterprise across Windows and Mac platforms. The advisory references over 100 individual CVEs disclosed by Microsoft's security bulletin dated 11 August 2026, with impacts ranging from remote code execution and privilege escalation to security bypass and confidentiality breaches.

No exploitation in the wild, proof-of-concept code, or specific threat actor activity is mentioned in the advisory. This is a standard vendor patch notification aggregated by the French national CERT, advising organizations to apply the vendor-supplied fixes referenced in the Microsoft Security Response Center update guide for each CVE. Given the scale of the update and reliance on Office as a common enterprise attack surface, organizations should prioritize patch deployment despite the absence of confirmed active exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-58651CVE-2026-62842CVE-2026-62882CVE-2026-63513CVE-2026-63515CVE-2026-63517CVE-2026-63518CVE-2026-63519CVE-2026-63521CVE-2026-63524CVE-2026-63525CVE-2026-63526CVE-2026-63527CVE-2026-63528CVE-2026-63529CVE-2026-63530CVE-2026-63531CVE-2026-63532CVE-2026-63533CVE-2026-64898CVE-2026-64899CVE-2026-64903CVE-2026-64904CVE-2026-64905CVE-2026-64906CVE-2026-64907CVE-2026-64908CVE-2026-64909CVE-2026-64910CVE-2026-64911CVE-2026-64912CVE-2026-64914CVE-2026-64915CVE-2026-64917CVE-2026-64919CVE-2026-64920CVE-2026-65656CVE-2026-65657CVE-2026-65661CVE-2026-65664

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1000

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free