VORANT. Threat Intelligence Sign in Get the full feed

Microsoft patches 114 Office flaws, four critical RCEs

routine vulnerability

Microsoft fixed 114 vulnerabilities across Office products, including four unauthenticated remote code execution flaws (CVSS 9.8) in Office, Outlook, and Skype.

NCSC-NL relayed Microsoft's Patch Tuesday advisory covering 114 vulnerabilities across Microsoft Office and related components (Outlook, Skype). The four most severe issues — CVE-2026-78505 (Office), CVE-2026-78509 and CVE-2026-78510 (Outlook), and CVE-2026-66302 (Skype) — carry a CVSS score of 9.8 and could allow an attacker to execute arbitrary code without prior authentication if they can reach the vulnerable component. The remaining 110 vulnerabilities range from medium to critical severity and cover a very broad set of weakness classes, including buffer overflows (stack, heap, over-read), use-after-free, type confusion, deserialization of untrusted data, SSRF, XSS, SQL injection, and improper signature verification, among others.

Exploitation of most of these flaws requires the attacker to convince a victim to open a malicious file or follow a malicious link — consistent with typical Office document/attachment-based attack chains rather than fully zero-click network exploitation, though this should be verified per-CVE via the MSRC portal. No in-the-wild exploitation is claimed in this advisory. Defenders should prioritize the four 9.8-rated RCE issues (Office, Outlook, Skype) for expedited patching given their unauthenticated exploitation potential, and roll out the broader monthly Office update set through standard patch management processes. Full technical details, affected build numbers, and any workarounds are available via the Microsoft Security Response Center (MSRC) portal referenced in the advisory.

This is a routine vendor patch bulletin aggregated by NCSC-NL rather than a report of active exploitation or a novel attack campaign; the primary action for defenders is timely deployment of the November/December 2026 Office security updates across Windows and Office deployments.

Mentioned in this report

Vulnerabilities CVE-2026-62804CVE-2026-63523CVE-2026-64918CVE-2026-66302CVE-2026-66303CVE-2026-66304CVE-2026-66305CVE-2026-66306CVE-2026-66307CVE-2026-66308CVE-2026-69268CVE-2026-69273CVE-2026-69282CVE-2026-69285CVE-2026-69402CVE-2026-69409CVE-2026-69417CVE-2026-69442CVE-2026-69464CVE-2026-69465CVE-2026-69477CVE-2026-69529CVE-2026-69559CVE-2026-69614CVE-2026-69615CVE-2026-69626CVE-2026-69629CVE-2026-69632CVE-2026-69636CVE-2026-69642CVE-2026-69646CVE-2026-69671CVE-2026-69678CVE-2026-69683CVE-2026-69686CVE-2026-78505CVE-2026-78509CVE-2026-78510

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0352.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free