Synced 16 Jun 2026 15:24 UTC Account
← Microsoft Office

Microsoft Office vulnerabilities: known CVEs & security history

Microsoft · Office / Productivity · 1031 tracked CVEs · 36 actively exploited · updated June 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all Microsoft Office release lines — 1031 in total, with 36 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Microsoft Office's current status and the safe version to run.

1031
known CVEs
36
actively exploited (KEV)
11
critical severity
3
ransomware-linked

Known Microsoft Office CVEs

Actively-exploited and most-severe first. Showing the top 80 of 1031. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2023-23397⚡ exploited critical 9.8 97% 2023
CVE-2023-35311⚡ exploited high 8.8 15% 2023
CVE-2019-1297⚡ exploited high 8.8 20% 2019
CVE-2019-0541⚡ exploited high 8.8 53% 2019
CVE-2018-0798⚡ exploited high 8.8 95% 2018
CVE-2015-2424⚡ exploited high 8.8 38% 2015
CVE-2015-1770⚡ exploited high 8.8 35% 2015
CVE-2012-1856⚡ exploited high 8.8 72% 2012
CVE-2012-1889⚡ exploited high 8.8 84% 2012
CVE-2012-0158⚡ exploited high 8.8 100% 2012
CVE-2009-0238⚡ exploited high 8.8 43% 2009
CVE-2007-0671⚡ exploited high 8.8 42% 2007
CVE-2006-2492⚡ exploited high 8.8 48% 2006
CVE-2026-21509⚡ exploited high 7.8 72% 2026
CVE-2021-42292⚡ exploited high 7.8 32% 2021
CVE-2021-38646⚡ exploited high 7.8 4% 2021
CVE-2018-0802⚡ exploited high 7.8 93% 2018
CVE-2017-11882⚡ exploited high 7.8 100% 2017
CVE-2017-8570⚡ exploited high 7.8 90% 2017
CVE-2017-0262⚡ exploited high 7.8 81% 2017
CVE-2017-0261⚡ exploited high 7.8 78% 2017
CVE-2017-0199⚡ exploited high 7.8 100% 2017
CVE-2016-7193⚡ exploited high 7.8 58% 2016
CVE-2015-2545⚡ exploited high 7.8 86% 2015
CVE-2015-1642⚡ exploited high 7.8 53% 2015
CVE-2015-1641⚡ exploited high 7.8 97% 2015
CVE-2014-1761⚡ exploited high 7.8 78% 2014
CVE-2013-3906⚡ exploited high 7.8 85% 2013
CVE-2013-1331⚡ exploited high 7.8 82% 2013
CVE-2012-1854⚡ exploited high 7.8 21% 2012
CVE-2010-3333⚡ exploited high 7.8 89% 2010
CVE-2009-3129⚡ exploited high 7.8 86% 2009
CVE-2009-0557⚡ exploited high 7.8 59% 2009
CVE-2009-0563⚡ exploited high 7.8 63% 2009
CVE-2021-27059⚡ exploited high 7.6 3% 2021
CVE-2023-36761⚡ exploited medium 6.5 19% 2023
CVE-2025-53766 critical 9.8 7% 2025
CVE-2023-21716 critical 9.8 82% 2023
CVE-2020-0901 critical 9.8 12% 2020
CVE-2019-1449 critical 9.8 6% 2019
CVE-2019-1205 critical 9.8 4% 2019
CVE-2016-7182 critical 9.8 30% 2016
CVE-2008-0081 critical 9.8 58% 2008
CVE-2023-33150 critical 9.6 2% 2023
CVE-2016-7277 critical 9.6 18% 2016
CVE-2019-1109 critical 9.1 4% 2019
CVE-2007-0065 high 10 43% 2008
CVE-2003-0347 high 10 68% 2003
CVE-2000-0854 high 10 37% 2000
CVE-2015-6172 high 9.3 55% 2015
CVE-2015-6124 high 9.3 14% 2015
CVE-2015-6118 high 9.3 14% 2015
CVE-2015-6108 high 9.3 26% 2015
CVE-2015-6107 high 9.3 18% 2015
CVE-2015-6106 high 9.3 18% 2015
CVE-2015-6093 high 9.3 23% 2015
CVE-2015-6092 high 9.3 15% 2015
CVE-2015-6091 high 9.3 15% 2015
CVE-2015-2510 high 9.3 36% 2015
CVE-2015-2477 high 9.3 14% 2015
CVE-2015-2470 high 9.3 27% 2015
CVE-2015-2469 high 9.3 27% 2015
CVE-2015-2468 high 9.3 43% 2015
CVE-2015-2467 high 9.3 28% 2015
CVE-2015-2466 high 9.3 17% 2015
CVE-2015-2464 high 9.3 36% 2015
CVE-2015-2463 high 9.3 34% 2015
CVE-2015-2456 high 9.3 36% 2015
CVE-2015-2455 high 9.3 37% 2015
CVE-2015-2435 high 9.3 22% 2015
CVE-2015-2431 high 9.3 30% 2015
CVE-2015-2380 high 9.3 14% 2015
CVE-2015-2379 high 9.3 14% 2015
CVE-2015-2376 high 9.3 16% 2015
CVE-2015-1760 high 9.3 16% 2015
CVE-2015-1683 high 9.3 14% 2015
CVE-2015-1682 high 9.3 21% 2015
CVE-2015-1650 high 9.3 29% 2015
CVE-2015-1649 high 9.3 26% 2015
CVE-2015-0086 high 9.3 15% 2015

951 older / lower-severity CVEs not shown — see Microsoft Office's full record.

Is my Microsoft Office version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your Microsoft Office version → · Monitor Microsoft Office for new CVEs →

Microsoft Office vulnerabilities — frequently asked

How many known vulnerabilities does Microsoft Office have?

IsItPatched tracks 1031 CVEs for Microsoft Office, 36 of which are actively exploited (CISA KEV). 11 are critical-severity and 847 high-severity. These span every release line — what matters is whether the version you run is affected.

Does Microsoft Office have any actively-exploited vulnerabilities?

Yes — 36 Microsoft Office CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (3 linked to ransomware). Patch these as a priority.

What is the most severe Microsoft Office vulnerability?

Among tracked issues, CVE-2023-23397 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Improper input validation weakness.

Is Microsoft Office safe to use?

It depends on the version. The latest supported Microsoft Office release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Microsoft Office security status · Microsoft Office end-of-life · actively-exploited CVEs. Always verify against Microsoft's advisories — see our disclaimer.