Microsoft Office: 25 Vulnerabilities Disclosed Together, Including High-Severity Flaws
Microsoft Office faces a batch of 25 vulnerabilities disclosed on August 11, 2026, featuring high-severity flaws like buffer overflows and command injection.

Key findings
- 25 Microsoft Office vulnerabilities disclosed on August 11, 2026, including high-severity flaws.
- Multiple buffer overflow vulnerabilities (heap and stack) allow for local code execution.
- Several vulnerabilities enable local information disclosure through improper input validation and out-of-bounds reads.
- Command injection flaws allow for privilege escalation or local code execution.
- All vulnerabilities were disclosed simultaneously, indicating a coordinated patch release.
Microsoft released a significant batch of 25 security vulnerabilities affecting its Office suite on August 11, 2026. This disclosure event, which saw all vulnerabilities published simultaneously, includes a mix of critical and medium-severity flaws, with a strong emphasis on remote code execution (RCE) and information disclosure. The vulnerabilities stem from various weaknesses, including buffer overflows, improper input validation, and use-after-free errors, posing a substantial risk to users if left unpatched.
A notable cluster of high-severity vulnerabilities (CVSSv3 7.8) centers around buffer overflows, specifically heap-based and stack-based, found in core Microsoft Office components and applications like Excel and Access. These flaws, including CVE-2026-70130, CVE-2026-68795, CVE-2026-66807, CVE-2026-65664, CVE-2026-65661, CVE-2026-65657, CVE-2026-64920, CVE-2026-64914, CVE-2026-64911, CVE-2026-64908, CVE-2026-64906, and CVE-2026-64898, could allow an unauthorized attacker to execute code locally.
Another group of high-severity vulnerabilities involves improper neutralization of special elements used in commands, leading to command injection. CVE-2026-68792 and CVE-2026-65656, both rated at CVSSv3 7.8, could permit an authorized or unauthorized attacker, respectively, to elevate privileges or execute code locally. Additionally, several vulnerabilities related to integer overflows/underflows (CVE-2026-64910, CVE-2026-64903, CVE-2026-64909) and untrusted pointer dereferences (CVE-2026-64910) also carry a high severity and the potential for local code execution.
Several medium-severity vulnerabilities (CVSSv3 5.5) focus on information disclosure. These include improper input validation (CVE-2026-70323, CVE-2026-70314, CVE-2026-64899) and out-of-bounds reads (CVE-2026-70315, CVE-2026-66809, CVE-2026-64899), which could allow an unauthorized attacker to access sensitive information locally. CVE-2026-70317, a use of uninitialized resource, also falls into this category.
While the provided information does not explicitly state which specific vulnerabilities are being exploited in the wild, related security advisories from Cisco Talos and Rapid7 indicate that Microsoft's August 2026 Patch Tuesday update, which includes this batch of Office vulnerabilities, addresses a total of 421 vulnerabilities, with 62 marked as critical. One vulnerability, CVE-2026-68820 (affecting Windows Ancillary Function Driver for WinSock), is noted as being exploited in the wild, though it is not part of this specific Office batch. However, the sheer volume and severity of the disclosed Office vulnerabilities suggest a high priority for patching.
Microsoft has addressed these vulnerabilities through its regular security update cycle. Users are strongly advised to update their Microsoft Office installations to the latest available versions to mitigate the risks associated with these flaws. Specific version numbers for patches are not detailed in the provided CVE descriptions, but the simultaneous disclosure implies a comprehensive update was released on August 11, 2026.
This coordinated disclosure of numerous vulnerabilities in Microsoft Office underscores the ongoing challenges in securing complex software suites. Users should prioritize applying all available security updates for Microsoft Office to protect against potential local code execution and information disclosure attacks. The concentration of high-severity flaws, particularly buffer overflows, highlights the critical need for diligent patch management.
CVE-2026-70323, CVE-2026-70317, CVE-2026-70315, CVE-2026-70314, CVE-2026-70130, CVE-2026-68795, CVE-2026-68792, CVE-2026-66809, CVE-2026-66807, CVE-2026-65664, CVE-2026-65661, CVE-2026-65657, CVE-2026-65656, CVE-2026-64920, CVE-2026-64914, CVE-2026-64911, CVE-2026-64910, CVE-2026-64909, CVE-2026-64908, CVE-2026-64906, CVE-2026-64904, CVE-2026-64903, CVE-2026-64899, CVE-2026-64898, CVE-2026-63533