VULNERABILITY INTELLIGENCECVE index
Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD. 18,947 CVE recordsPage 318 of 1264 · EPSS data 2026.07.28
ReviewHigh
CVE-2026-55039Microsoft Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55038Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55037Microsoft Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55036Microsoft Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55034Microsoft Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55033Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55032Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55031Microsoft Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55029Microsoft Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55025Microsoft Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55024Microsoft Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55022Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55021Microsoft Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55018Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.ReviewHigh
CVE-2026-55017Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.