Synced 16 Jun 2026 15:24 UTC Account
← All patching guides

How to patch Microsoft Office

Microsoft · Office / Productivity · 5 steps · Microsoft Office security status → · updated June 2026

How you patch Office depends on the install type. Modern Microsoft 365 / Office 2016+ use Click-to-Run (update in-app); older volume installs use Windows/Microsoft Update.

36
actively exploited (KEV)
1,031
tracked CVEs
latest supported

Microsoft Office has 36 actively-exploited vulnerabilities on the CISA KEV list — patching is urgent.

Check your current version first

Before you patch, record what you're running (Any Office app):

File → Account → About (shows version & build)

Or paste your version into the checker for an instant verdict.

Step by step

1
Identify the install type

Open any Office app → File → Account. If you see "Update Options" it is Click-to-Run; volume (MSI) installs patch through Windows Update instead.

2
Update Click-to-Run

File → Account → Update Options → Update Now. For managed fleets, use the Microsoft 365 Apps admin center / update channels, or push via SCCM/Intune.

3
Update MSI / volume installs

Apply the latest Office security updates via Microsoft Update, WSUS or the Microsoft Update Catalog (by KB).

4
Restart the apps

Close and reopen Office apps to finish applying the update.

5
Verify

Check File → Account → About to confirm the new version/build.

Watch out for:
  • Malicious documents and macros are a top Office attack vector — keep Protected View and macro-blocking enabled.
  • Pick an update channel deliberately for managed estates so security updates arrive on a predictable cadence.

Official sources

Don't patch blind. Microsoft Office has 36 actively-exploited vulnerabilities on the CISA KEV list — patching is urgent. See exactly which versions are safe and what you're exposed to.

Microsoft Office security status →

Stay ahead of the next one

Frequently asked questions

What is the latest version of Microsoft Office?

Check the current supported Microsoft Office release on its product page or the official vendor advisory, then patch to it.

How do I check which version of Microsoft Office I am running?

Use: File → Account → About (shows version & build) (Any Office app). Record the result before and after patching to confirm the update applied.

Is Microsoft Office being actively exploited right now?

Yes — 36 Microsoft Office vulnerabilities are on the CISA Known Exploited Vulnerabilities (KEV) list, so attackers are using them in the wild. Patch promptly. See the exploitation radar.

How do I patch Microsoft Office safely without breaking production?

Always test in a non-production environment first, take a backup or snapshot, follow the official vendor advisory, and have a tested rollback. Patch one node at a time for clustered or high-availability setups.

Patch steps are general, well-established guidance for Microsoft Office — always test in a non-production environment first and follow the official Microsoft advisory for your exact version. IsItPatched is independent and not affiliated with Microsoft; this is not a substitute for vendor documentation. See our disclaimer.

← All patching guides · Security guides →