Security Risk Category

Microsoft Security Risks — Page 2

Published vulnerability pages connected to Microsoft. Each page keeps one canonical URL and focused remediation guidance.

212 published Microsoft risks

Microsoft risks

Showing 37–72 of 212 published risks.

highEPSS 0.003

CVE-2026-55017 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55017microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55018 365 apps vulnerability

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55018microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-55022 365 apps vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55022microsoftmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55023 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55023microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55026 365 apps vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55026microsoftinput-validation

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55027 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55027microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55028 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55028microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55032 365 apps vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55032microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.005

CVE-2026-55033 365 apps vulnerability

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55033microsoftinput-validationmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55035 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55035microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55036 365 apps vulnerability

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55036microsoft

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55037 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55037microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-55038 365 apps vulnerability

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55038microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55039 365 apps vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55039microsoftinput-validationmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55041 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55041microsoftmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55042 365 apps vulnerability

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55042microsoft

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55043 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2026-55043microsoftinput-validationmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55044 365 apps vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55044microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55045 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55045microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55046 365 apps vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55046microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55047 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55047microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55049 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55049microsoftmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55050 365 apps vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55050microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.006

CVE-2026-55051 sharepoint server vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVE-2026-55051microsoftssrf

Updated Jul 17, 2026

highEPSS 0.005

CVE-2026-55052 sharepoint server vulnerability

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-55052microsoftauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55055 365 apps vulnerability

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55055microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55056 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55056microsoftmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55057 365 apps vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55057microsoftinput-validation

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55123 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2026-55123microsoftmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55124 365 apps vulnerability

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55124microsoftinput-validation

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55125 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55125microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.005

CVE-2026-55126 sharepoint server vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55126microsoftxss

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55127 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55127microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55128 365 apps vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55128microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55129 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55129microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-55132 365 apps vulnerability

Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55132microsoft

Updated Jul 17, 2026