Multiples vulnérabilités dans Microsoft Office (09 septembre 2026)
Multiple vulnerabilities have been discovered in Microsoft Office, enabling an attacker to cause arbitrary code execution, data confidentiality breaches, and bypass security policies. These vulnerabilities affect a wide range of Office products across various versions, including desktop and online applications. The CERT-FR bulletin details numerous CVEs related to these issues, highlighting the need for immediate patching and updates.
Multiple vulnerabilities have been discovered in Microsoft Office, enabling an attacker to cause arbitrary code execution, data confidentiality breaches, and bypass security policies. These vulnerabilities affect a wide range of Office products across various versions, including desktop and online applications. The CERT-FR bulletin details numerous CVEs related to these issues, highlighting the need for immediate patching and updates.
**What happened**
Several vulnerabilities exist within Microsoft Office, presenting significant security risks. These vulnerabilities allow an attacker to potentially execute arbitrary code, compromise data confidentiality, and circumvent existing security policies. The vulnerabilities span multiple Office applications, including Microsoft 365 Apps for Enterprise, Office LTSC 2021, and Office Online Server. The bulletin details numerous CVEs (Common Vulnerabilities and Exposures) associated with these issues, each with a specific description and severity level.
Specifically, the bulletin lists CVEs such as CVE-2026-62804, CVE-2026-64918, CVE-2026-69285, CVE-2026-69442, CVE-2026-69477, CVE-2026-69529, CVE-2026-69556, CVE-2026-69614, CVE-2026-69626, CVE-2026-69629, CVE-2026-69632, CVE-2026-69671, CVE-2026-69678, CVE-2026-69686, CVE-2026-69719, CVE-2026-69722, CVE-2026-69734, CVE-2026-69739, CVE-2026-69742, CVE-2026-69759, CVE-2026-69764, CVE-2026-69767, CVE-2026-69778, CVE-2026-69797, CVE-2026-72938, CVE-2026-72956, CVE-2026-72972, CVE-2026-72973, CVE-2026-72974, CVE-2026-72975, CVE-2026-72976, CVE-2026-72977, CVE-2026-78439, CVE-2026-78502, CVE-2026-78503, CVE-2026-78504, CVE-2026-78505, CVE-26-78506, CVE-26-78507, CVE-26-78509, CVE-26-78510, CVE-26-78511, CVE-26-78512, CVE-26-78513, CVE-26-78514, CVE-26-78515, CVE-26-78517, and CVE-26-78518. The bulletin emphasizes the need to refer to the Microsoft Security Response Center (MSRC) for the most up-to-date information and recommended solutions.
**Technical details** The vulnerabilities affect a wide range of Office products, including Microsoft 365 Apps for Enterprise, Office LTSC 2021, Office Online Server, and various desktop versions of Office. The vulnerabilities are categorized as remote code execution (RCE), data confidentiality breaches, and policy bypass. The bulletin details specific attack vectors and exploitation status for each CVE.
**Impact** The exploitation of these vulnerabilities could lead to significant data breaches, system compromise, and potential denial of service. Attackers could gain unauthorized access to sensitive information, execute malicious code, and disrupt Office services. The impact extends to organizations using Office products, potentially exposing user data and critical systems.
**What to do**
- Refer to the Microsoft Security Response Center (MSRC) for the most up-to-date information and recommended solutions: [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62804](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62804) and other linked bulletins.
- Apply the latest security updates and patches for all affected Office products immediately.
- Regularly scan your systems for vulnerabilities and ensure that your security infrastructure is properly configured.
- Implement a robust vulnerability management program to proactively identify and address security risks.
**Why it matters** The widespread nature of Microsoft Office means that these vulnerabilities pose a significant threat to a vast number of organizations and individuals. Prompt patching and proactive security measures are crucial to mitigate the risk of exploitation and protect sensitive data. Ignoring these vulnerabilities could lead to serious consequences, including data loss, financial damage, and reputational harm.