CyberMax
Home › Exploited CVEs › Microsoft

Microsoft Office known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 29 Microsoft Office CVEs as exploited in the wild. 4 were added in the last 12 months and 3 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 29 Microsoft Office CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2017-11882Office Memory Corruption99.94%Yes2021-11-032022-05-03
2CVE-2023-23397Office Outlook Privilege Escalation97.2%–2023-03-142023-04-04
3CVE-2015-1641Office Memory Corruption96.7%–2021-11-032022-05-03
4CVE-2018-0798Office Memory Corruption95.1%–2021-11-032022-05-03
5CVE-2018-0802Office Memory Corruption93.3%Yes2021-11-032022-05-03
6CVE-2017-8570Office Remote Code Execution89.9%–2022-02-252022-08-25
7CVE-2010-3333Office Stack-based Buffer Overflow89.5%–2022-03-032022-03-24
8CVE-2015-2545Office Malformed EPS File85.9%–2022-03-032022-03-24
9CVE-2017-11826Office Remote Code Execution81.2%–2022-03-032022-03-24
10CVE-2017-0262Office Remote Code Execution81.0%–2022-02-102022-08-10
11CVE-2013-1331Office Buffer Overflow79.8%–2022-06-082022-06-22
12CVE-2017-0261Office Use-After-Free78.1%–2022-03-032022-03-24
13CVE-2012-1856Office MSCOMCTL.OCX Remote Code Execution72.0%–2022-03-032022-03-24
14CVE-2026-21509Office Security Feature Bypass70.8%–2026-01-262026-02-16
15CVE-2009-0556Office PowerPoint Code Injection67.3%–2026-01-072026-01-28
16CVE-2009-0563Office Buffer Overflow62.8%–2022-06-082022-06-22
17CVE-2017-11774Office Outlook Security Feature Bypass59.6%–2021-11-032022-05-03
18CVE-2016-7193Office Memory Corruption57.6%–2022-03-032022-03-24
19CVE-2015-1642Office Memory Corruption53.1%–2022-03-032022-03-24
20CVE-2009-0557Office Object Record Corruption53.0%–2022-06-082022-06-22
21CVE-2016-3235Office OLE DLL Side Loading43.3%–2021-11-032022-05-03
22CVE-2007-0671Office Excel Remote Code Execution43.2%–2025-08-122025-09-02
23CVE-2009-0238Office Remote Code Execution43.2%–2026-04-142026-04-28
24CVE-2021-42292Excel Security Feature Bypass43.0%–2021-11-172021-12-01
25CVE-2015-1770Office Uninitialized Memory Use35.0%–2022-03-282022-04-18
26CVE-2023-21715Office Publisher Security Feature Bypass12.0%–2023-02-142023-03-07
27CVE-2021-38646Office Access Connectivity Engine Remote Code Execution8.0%Yes2022-03-282022-04-18
28CVE-2021-27059Office Remote Code Execution6.1%–2021-11-032021-11-17
29CVE-2026-21514Office Word Reliance on Untrusted Inputs in a Security Decision1.6%–2026-02-102026-03-03
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · Windows · SharePoint Server · Defender · Internet Explorer · Exchange Server · Win32k · free KEV badge for Microsoft · all vendors