Microsoft Office known exploited vulnerabilities, ranked
CISA lists 29 Microsoft Office CVEs as exploited in the wild. 4 were added in the last 12 months and 3 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2017-11882: EPSS 99.94%, used in ransomware, added 2021-11-03
- CVE-2023-23397: EPSS 97.2%, added 2023-03-14
- CVE-2015-1641: EPSS 96.7%, added 2021-11-03
- CVE-2018-0798: EPSS 95.1%, added 2021-11-03
- CVE-2018-0802: EPSS 93.3%, used in ransomware, added 2021-11-03
All 29 Microsoft Office CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2017-11882 | Office Memory Corruption | 99.94% | Yes | 2021-11-03 | 2022-05-03 |
| 2 | CVE-2023-23397 | Office Outlook Privilege Escalation | 97.2% | – | 2023-03-14 | 2023-04-04 |
| 3 | CVE-2015-1641 | Office Memory Corruption | 96.7% | – | 2021-11-03 | 2022-05-03 |
| 4 | CVE-2018-0798 | Office Memory Corruption | 95.1% | – | 2021-11-03 | 2022-05-03 |
| 5 | CVE-2018-0802 | Office Memory Corruption | 93.3% | Yes | 2021-11-03 | 2022-05-03 |
| 6 | CVE-2017-8570 | Office Remote Code Execution | 89.9% | – | 2022-02-25 | 2022-08-25 |
| 7 | CVE-2010-3333 | Office Stack-based Buffer Overflow | 89.5% | – | 2022-03-03 | 2022-03-24 |
| 8 | CVE-2015-2545 | Office Malformed EPS File | 85.9% | – | 2022-03-03 | 2022-03-24 |
| 9 | CVE-2017-11826 | Office Remote Code Execution | 81.2% | – | 2022-03-03 | 2022-03-24 |
| 10 | CVE-2017-0262 | Office Remote Code Execution | 81.0% | – | 2022-02-10 | 2022-08-10 |
| 11 | CVE-2013-1331 | Office Buffer Overflow | 79.8% | – | 2022-06-08 | 2022-06-22 |
| 12 | CVE-2017-0261 | Office Use-After-Free | 78.1% | – | 2022-03-03 | 2022-03-24 |
| 13 | CVE-2012-1856 | Office MSCOMCTL.OCX Remote Code Execution | 72.0% | – | 2022-03-03 | 2022-03-24 |
| 14 | CVE-2026-21509 | Office Security Feature Bypass | 70.8% | – | 2026-01-26 | 2026-02-16 |
| 15 | CVE-2009-0556 | Office PowerPoint Code Injection | 67.3% | – | 2026-01-07 | 2026-01-28 |
| 16 | CVE-2009-0563 | Office Buffer Overflow | 62.8% | – | 2022-06-08 | 2022-06-22 |
| 17 | CVE-2017-11774 | Office Outlook Security Feature Bypass | 59.6% | – | 2021-11-03 | 2022-05-03 |
| 18 | CVE-2016-7193 | Office Memory Corruption | 57.6% | – | 2022-03-03 | 2022-03-24 |
| 19 | CVE-2015-1642 | Office Memory Corruption | 53.1% | – | 2022-03-03 | 2022-03-24 |
| 20 | CVE-2009-0557 | Office Object Record Corruption | 53.0% | – | 2022-06-08 | 2022-06-22 |
| 21 | CVE-2016-3235 | Office OLE DLL Side Loading | 43.3% | – | 2021-11-03 | 2022-05-03 |
| 22 | CVE-2007-0671 | Office Excel Remote Code Execution | 43.2% | – | 2025-08-12 | 2025-09-02 |
| 23 | CVE-2009-0238 | Office Remote Code Execution | 43.2% | – | 2026-04-14 | 2026-04-28 |
| 24 | CVE-2021-42292 | Excel Security Feature Bypass | 43.0% | – | 2021-11-17 | 2021-12-01 |
| 25 | CVE-2015-1770 | Office Uninitialized Memory Use | 35.0% | – | 2022-03-28 | 2022-04-18 |
| 26 | CVE-2023-21715 | Office Publisher Security Feature Bypass | 12.0% | – | 2023-02-14 | 2023-03-07 |
| 27 | CVE-2021-38646 | Office Access Connectivity Engine Remote Code Execution | 8.0% | Yes | 2022-03-28 | 2022-04-18 |
| 28 | CVE-2021-27059 | Office Remote Code Execution | 6.1% | – | 2021-11-03 | 2021-11-17 |
| 29 | CVE-2026-21514 | Office Word Reliance on Untrusted Inputs in a Security Decision | 1.6% | – | 2026-02-10 | 2026-03-03 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · Windows · SharePoint Server · Defender · Internet Explorer · Exchange Server · Win32k · free KEV badge for Microsoft · all vendors