PatchSiren

Microsoft CVE debriefs · Page 35

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55133

CVE-2026-55133 is a heap-based buffer overflow vulnerability in Microsoft Office OneNote, allowing unauthorized attackers to execute code locally. This vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Users of Microsoft Office OneNote, particularly those in environments where local code execution could have significant impacts, should prioritize patching this vulnerability. The CVE r [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55132

CVE-2026-55132 is a high-severity vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally due to a double free issue. The CVE record was published on 2026-07-14T18:18:19.850Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Microsoft 365 Apps, Office 2019, Office 2021, Office 2024, and SharePoint Server. Users [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55129

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:19.463Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects various versions of Microsoft Office, including 365 Apps, Office 2016, Office 2019, Office 2021, and Office 2024. A heap-based buffer overflow vulnerability exists, which could allo [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55128

CVE-2026-55128 is a high-severity vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally. The vulnerability is caused by a use-after-free issue in Microsoft Office Word. This type of vulnerability can be particularly dangerous as it allows attackers to execute arbitrary code, potentially leading to a complete compromise of the affected system. Users should be c [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55127

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:19.180Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-55127, is a heap-based buffer overflow in Microsoft Office Word, which could allow an unauthorized attacker to execute code locally. The vulnerability has been assigned a CVSS sco [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55126

CVE-2026-55126 is a high-severity vulnerability in Microsoft Office SharePoint, allowing an authorized attacker to perform spoofing over a network. The vulnerability has a CVSS score of 7.3 and is classified as HIGH. Microsoft has provided a patch and vendor advisory for this issue. Affected product deployments should be reviewed, and owners assigned for follow-up. The vulnerability is caused by improper [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55125

The CVE-2026-55125 vulnerability is a heap-based buffer overflow in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Security teams and administrators responsible for Microsoft Office and related products should be aware of this vulnerability. The CVE record was published on 2026-07-14T18:18:18.9 [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55124

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:18.767Z and has not been modified since then. This information disclosure vulnerability in Microsoft Office Word, caused by improper validation of specified types of input, allows an unauthorized attacker to disclose information locally. Organizations should be aware of the potential risks [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55123

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:18.633Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, a heap-based buffer overflow in Microsoft Office PowerPoint, allows an unauthorized attacker to execute code locally, impacting users of various Office versions, including 2016, 2019, 2021, and 2024.

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55057

CVE-2026-55057 is an integer overflow or wraparound vulnerability in Microsoft Office. The vulnerability allows an unauthorized attacker to disclose information locally. Microsoft has released a patch for this vulnerability. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. System administrators and users of Microsoft Office should be aware of this vulnerability and take steps to mitigate it.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55056

A heap-based buffer overflow vulnerability exists in Microsoft Office, which could allow an unauthorized attacker to execute code locally. The vulnerability has been assigned a CVSS score of 7.8 and a severity of HIGH. It affects various versions of Microsoft Office, including 365 Apps, Office 2016, Office 2019, Office 2021, and Office 2024. Users of Microsoft Office, particularly those using 365 Apps, Of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55055

CVE-2026-55055 is a stack-based buffer overflow vulnerability in Microsoft Office Word. An unauthorized attacker could exploit this vulnerability to execute code locally. The CVE record was published on 2026-07-14T18:18:17.683Z and has not been modified since then. This vulnerability affects multiple versions of Microsoft Office, including Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps. Users shoul [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55051

CVE-2026-55051 is a server-side request forgery (SSRF) vulnerability in Microsoft Office SharePoint. An authorized attacker can exploit this vulnerability to disclose information over a network. The vulnerability has a CVSS score of 6.5 and a severity rating of MEDIUM. Affected product deployments should be reviewed for potential exposure, and owners should be assigned for follow-up. The CVE record was pu [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55050

An out-of-bounds read vulnerability exists in Microsoft Office Word, which could allow an unauthorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. This issue affects users of Microsoft Office Word, particularly those in environments where the software is used extensively. It is essential to be aware of this vulnerability and take necessary [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55049

A heap-based buffer overflow vulnerability exists in Microsoft Office, allowing an unauthorized attacker to execute code locally. This CVE record was published on 2026-07-14T18:18:16.860Z. The vulnerability affects various versions of Microsoft Office, including 2016, 2019, 2021, and 2024, across different architectures. Users should review and apply patches to prevent local code execution. The CVSS score [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55047

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-55047 was published on 2026-07-14T18:18:16.503Z. This out-of-bounds read vulnerability in Microsoft Office allows an unauthorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. It affects various versions of Microsoft Office, including Office 2019, [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55046

CVE-2026-55046 is an out-of-bounds read vulnerability in Microsoft Office Excel. The CVE record was published on 2026-07-14T18:18:16.353Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability affects multiple versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and Office 2024. Users of Microsoft Office Excel should be aware of this vulnerab [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55045

CVE-2026-55045 is an out-of-bounds read vulnerability in Microsoft Office, allowing unauthorized attackers to execute code locally. This vulnerability affects various versions of Microsoft Office, including 365 Apps, Office 2016, Office 2019, Office 2021, Office 2024, and SharePoint Server. Users should be aware of this high-severity vulnerability, which has a CVSS score of 8.4. The CVE record was publish [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55042

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:15.730Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-55042, involves the use of an uninitialized resource in Microsoft Office, which could allow an unauthorized attacker to disclose information locally. The vulnerability has a CVSS [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55041

CVE-2026-55041 is a heap-based buffer overflow vulnerability in Microsoft Office Excel, allowing unauthorized attackers to execute code locally. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Users of Microsoft Office Excel, particularly those with high-risk exposure or handling sensitive data, should prioritize patching this vulnerability to prevent local code execution. T [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55039

CVE-2026-55039 is an integer underflow vulnerability in Microsoft Office Excel, allowing unauthorized attackers to execute code locally. This CVE record was published on 2026-07-14T18:18:15.257Z. The vulnerability, tracked under CWE-122 and CWE-191, has a CVSS score of 7.8 with a severity of HIGH. Users of Microsoft Office Excel, particularly those using 2016, 2019, 2021, and 2024 versions, as well as Mic [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55035

CVE-2026-55035 is an out-of-bounds read vulnerability in Microsoft Office. The CVE record was published on 2026-07-14T18:18:14.557Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects various versions of Microsoft Office, including 365 Apps, Office 2016, Office 2019, Office 2021, Office 2024, and SharePoint Server. Users should review their deployments and [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55033

CVE-2026-55033 is an integer overflow or wraparound vulnerability in Microsoft Office Word, classified as HIGH severity with a CVSS score of 7.8. The vulnerability allows an unauthorized attacker to execute code locally. It was published on 2026-07-14T18:18:14.293Z and last modified on 2026-07-16T16:13:17.387Z. The vulnerability exists due to improper handling of integer values in Microsoft Office Word, w [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55032

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:14.150Z and has not been modified since then. CVE-2026-55032 is a use-after-free vulnerability in Microsoft Office Word, classified as HIGH severity with a CVSSv3.1 score of 7.8. This vulnerability allows an unauthorized attacker to execute code locally, potentially leading to system compro [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55028

CVE-2026-55028 is an out-of-bounds read vulnerability in Microsoft Office, specifically affecting 365 Apps, Office 2016, Office 2019, Office 2021, and Office 2024. This vulnerability allows an unauthorized attacker to disclose information locally. The CVE record was published on 2026-07-14T18:18:13.613Z and has not been modified since then. The NVD entry is currently Analyzed. Users should review their Of [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55027

CVE-2026-55027 is an out-of-bounds read vulnerability in Microsoft Office. The CVE record was published on 2026-07-14T18:18:13.473Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects various versions of Microsoft Office, including 365 Apps, Office 2016, Office 2019, Office 2021, Office 2024, and SharePoint Server. Users should review their deployments and [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55026

CVE-2026-55026 is an integer overflow or wraparound vulnerability in Microsoft Office, specifically affecting versions such as 365 Apps, Office 2016, Office 2019, Office 2021, and Office 2024. This vulnerability allows an unauthorized attacker to disclose information locally. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 6.2, with a severity rating of MEDIUM. Users of Micr [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55023

CVE-2026-55023 is an out-of-bounds read vulnerability in Microsoft Office, allowing unauthorized attackers to disclose information locally. The CVE record was published on 2026-07-14T18:18:12.913Z. The vulnerability affects various versions of Microsoft Office, including 365 Apps, Office 2016, Office 2019, Office 2021, Office 2024, and SharePoint Server. Users should apply patches provided by Microsoft an [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55022

A high-severity type confusion vulnerability exists in Microsoft Office, tracked as CVE-2026-55022. This vulnerability allows an unauthorized attacker to execute code locally, with a CVSS score of 7.8. The CVE record was published on 2026-07-14T18:18:12.780Z and has not been modified since then. The vulnerability is caused by a type confusion issue in Microsoft Office. An attacker can exploit this vulnera [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55020

CVE-2026-55020 is a cross-site scripting vulnerability in Microsoft Office SharePoint. An authorized attacker can perform spoofing over a network by exploiting this vulnerability. The CVSS score is 4.6, and the severity is MEDIUM. This vulnerability affects Microsoft Office SharePoint users and administrators. It is essential to review and apply the available patch to prevent potential cross-site scripting attacks.