Product of Microsoft

Word

As of , 4 Microsoft Word vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2014-1761.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2014-1761Memory CorruptionMicrosoft WordPatch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry0.77
2CVE-2012-2539Remote Code ExecutionMicrosoft WordPatch this weekEPSS 0.530.53
3CVE-2006-2492Malformed Object PointerMicrosoft WordPatch soon0.48
4CVE-2023-36761Information DisclosureMicrosoft WordPatch soon0.20

Added each year

1232022: 3320222023: 1120232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20223
20231
2024none
2025none
2026none

Used in ransomware