Microsoft Office: 22 Vulnerabilities Including RCE Flaws Disclosed Together
Key findings • Microsoft Office: 22 vulnerabilities disclosed simultaneously on September 8, 2026. • Flaws include critical and high-severity remote code execution bugs in Word, Excel, and ot…

Key findings
- Microsoft Office: 22 vulnerabilities disclosed simultaneously on September 8, 2026.
- Flaws include critical and high-severity remote code execution bugs in Word, Excel, and other Office components.
- Medium-severity flaws allow for information disclosure and spoofing.
- Vulnerabilities range from buffer overflows and use-after-free to out-of-bounds reads and type confusion.
- Part of a record-breaking September 2026 Patch Tuesday release, with some related CVEs exploited in the wild.
On September 8, 2026, Microsoft released a significant security update addressing a batch of 22 vulnerabilities affecting its Office suite. This coordinated disclosure, all published within a span of 3 hours, includes a range of issues from information disclosure to remote code execution. The vulnerabilities span various components of Microsoft Office, including Excel, Word, and Outlook, with several critical and high-severity flaws that could allow attackers to execute code on a victim's machine.
The disclosed vulnerabilities can be broadly categorized by their impact and the affected Office application:
Information Disclosure Vulnerabilities
Several medium-severity vulnerabilities were disclosed, primarily allowing for local or network-based information disclosure. These include out-of-bounds read flaws in Microsoft Office Excel (CVE-2026-85875, CVE-2026-81393), use of uninitialized resources in Microsoft Office (CVE-2026-80091), heap-based buffer overflows (CVE-2026-80087), out-of-bounds reads in Outlook (CVE-2026-80084), and type confusion vulnerabilities in PowerPoint (CVE-2026-72938). Additionally, buffer over-reads (CVE-2026-69626) and other out-of-bounds reads (CVE-2026-69739) in Microsoft Office also fall into this category. One vulnerability in Microsoft Office specifically allows for spoofing over a network due to insufficiently protected credentials (CVE-2026-64918).
Remote Code Execution Vulnerabilities
A significant portion of the batch consists of high and critical severity vulnerabilities that could lead to remote code execution. These include stack-based buffer overflows in Microsoft Office Excel (CVE-2026-81396), out-of-bounds writes in Microsoft Office (CVE-2026-78524), and heap-based buffer overflows in Microsoft Office Word (CVE-2026-78510, CVE-2026-78505, CVE-2026-77898, CVE-2026-69442, CVE-2026-69285). Use-after-free vulnerabilities in Microsoft Office (CVE-2026-69632) also present a risk of code execution. The critical severity flaw, CVE-2026-78510, is a heap-based buffer overflow in Microsoft Office Word, posing a severe threat.
Exploitation and Response
Microsoft's September 2026 Patch Tuesday release addressed these vulnerabilities alongside a record-breaking number of other CVEs. While the provided information does not explicitly state that this specific batch of 22 Office vulnerabilities were exploited in the wild, related news coverage indicates that Microsoft was aware of exploitation for two zero-day vulnerabilities in the broader September release N2, N3, N4. Users of Microsoft Office are strongly advised to apply the latest security updates provided by Microsoft to mitigate these risks. The specific versions affected and patched are detailed in Microsoft's official security advisories.
This coordinated disclosure highlights the ongoing efforts by Microsoft to address security flaws within its widely used Office suite. Users should remain vigilant and ensure their software is up-to-date to protect against potential exploitation of these and other vulnerabilities. The sheer volume of vulnerabilities disclosed in this single event underscores the importance of timely patching and robust security practices for enterprise environments.