{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Microsoft heeft kwetsbaarheden verholpen in diverse Office-producten.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "Een kwaadwillende kan de kwetsbaarheden misbruiken om zich voor te doen als andere gebruiker, toegang te krijgen tot gevoelige gegevens of willekeurige code uit te voeren in de context van het slachtoffer.\n\nVoor succesvol misbruik moet de kwaadwillende geauthenticeerd zijn op het kwetsbare systeem, of het slachtoffer misleiden een malafide bestand te openen of link te volgen.\n\nVan de kwetsbaarheid met kenmerk CVE-2026-20963 wordt gemeld dat deze actief en gericht is misbruikt. De kwetsbaarheid stelt een kwaadwillende in staat om willekeurige code uit te voeren op een kwetsbaar Sharepoint systeem. Met name publiek toegankelijke installaties lopen verhoogd risico op misbruik.\nBuiten meldingen van actief misbruik is (nog) geen publieke Proof-of-Concept-code of exploit bekend. Door de media-aandacht echter, verwacht het NCSC dat deze wellicht op korte termijn beschikbaar komt, waardoor het risico op grootschalig misbruik zal toenemen.\n\n```\nMicrosoft Office Word: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2026-20944 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20948 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office SharePoint: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2026-20947 | 8.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20951 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20959 | 4.60 | Voordoen als andere gebruiker       | \n| CVE-2026-20963 | 8.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20958 | 5.40 | Toegang tot gevoelige gegevens      | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2026-20943 | 7.00 | Uitvoeren van willekeurige code     | \n| CVE-2026-20953 | 8.40 | Uitvoeren van willekeurige code     | \n| CVE-2026-20952 | 8.40 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nMicrosoft Office Excel: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2026-20946 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20955 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20956 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20949 | 7.80 | Omzeilen van beveiligingsmaatregel  | \n| CVE-2026-20950 | 7.80 | Uitvoeren van willekeurige code     | \n| CVE-2026-20957 | 7.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n```",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Microsoft heeft updates beschikbaar gesteld waarmee de beschreven kwetsbaarheden worden verholpen. We raden u aan om deze updates te installeren. Meer informatie over de kwetsbaarheden, de installatie van de updates en eventuele work-arounds vindt u op:\n\nhttps://portal.msrc.microsoft.com/en-us/security-guidance",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Improper Input Validation",
                "title": "CWE-20"
            },
            {
                "category": "general",
                "text": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
                "title": "CWE-79"
            },
            {
                "category": "general",
                "text": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
                "title": "CWE-89"
            },
            {
                "category": "general",
                "text": "Heap-based Buffer Overflow",
                "title": "CWE-122"
            },
            {
                "category": "general",
                "text": "Out-of-bounds Read",
                "title": "CWE-125"
            },
            {
                "category": "general",
                "text": "Integer Underflow (Wrap or Wraparound)",
                "title": "CWE-191"
            },
            {
                "category": "general",
                "text": "Improper Access Control",
                "title": "CWE-284"
            },
            {
                "category": "general",
                "text": "Use After Free",
                "title": "CWE-416"
            },
            {
                "category": "general",
                "text": "Untrusted Search Path",
                "title": "CWE-426"
            },
            {
                "category": "general",
                "text": "Deserialization of Untrusted Data",
                "title": "CWE-502"
            },
            {
                "category": "general",
                "text": "Untrusted Pointer Dereference",
                "title": "CWE-822"
            },
            {
                "category": "general",
                "text": "Server-Side Request Forgery (SSRF)",
                "title": "CWE-918"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "Kwetsbaarheden verholpen in Microsoft Office",
        "tracking": {
            "current_release_date": "2026-03-20T14:03:59.225773Z",
            "generator": {
                "date": "2025-08-04T16:30:00Z",
                "engine": {
                    "name": "V.A.",
                    "version": "1.3"
                }
            },
            "id": "NCSC-2026-0010",
            "initial_release_date": "2026-01-13T19:18:45.984019Z",
            "revision_history": [
                {
                    "date": "2026-01-13T19:18:45.984019Z",
                    "number": "1.0.0",
                    "summary": "Initiele versie"
                },
                {
                    "date": "2026-03-20T14:03:59.225773Z",
                    "number": "1.0.1",
                    "summary": "Er worden berichten gepubliceerd dat de kwetsbaarheid met kenmerk CVE-2026-20963 gericht en actief wordt misbruikt."
                }
            ],
            "status": "final",
            "version": "1.0.1"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-1"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft 365 Apps for Enterprise"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-2"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft 365 Apps for Enterprise for 32-bit Systems"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-3"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft 365 Apps for Enterprise for 64-bit Systems"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-4"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Excel 2016"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Excel 2016 (32-bit edition)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-6"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Excel 2016 (64-bit edition)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-7"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office 2016"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-8"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office 2016 (32-bit edition)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-9"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office 2016 (64-bit edition)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-10"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office 2019"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-11"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office 2019 for 32-bit editions"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-12"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office 2019 for 64-bit editions"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-13"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office Deployment Tool"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-14"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC 2021"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-15"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC 2021 for 32-bit editions"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-16"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC 2021 for 64-bit editions"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-17"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC 2024"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-18"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC 2024 for 32-bit editions"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-19"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC 2024 for 64-bit editions"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-20"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC for Mac 2021"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-21"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Office LTSC for Mac 2024"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-22"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft SharePoint Enterprise Server 2016"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-23"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft SharePoint Server 2019"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-24"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft SharePoint Server Subscription Edition"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-25"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Word 2016"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-26"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Word 2016 (32-bit edition)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-27"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Microsoft Word 2016 (64-bit edition)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-28"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Office Online Server"
                    }
                ],
                "category": "vendor",
                "name": "Microsoft"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-20943",
            "cwe": {
                "id": "CWE-426",
                "name": "Untrusted Search Path"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Search Path",
                    "title": "CWE-426"
                },
                {
                    "category": "description",
                    "text": "An untrusted search path vulnerability in Microsoft Office allows an attacker to execute unauthorized local code by exploiting the way Office handles file paths.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20943 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20943.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20943"
        },
        {
            "cve": "CVE-2026-20947",
            "cwe": {
                "id": "CWE-89",
                "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
                    "title": "CWE-89"
                },
                {
                    "category": "description",
                    "text": "An SQL injection vulnerability in Microsoft Office SharePoint allows authorized users to remotely execute code over a network, posing a significant security risk.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20947 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20947.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20947"
        },
        {
            "cve": "CVE-2026-20951",
            "notes": [
                {
                    "category": "description",
                    "text": "Improper input validation in Microsoft Office SharePoint allows attackers to execute unauthorized local code, posing a significant security risk.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20951 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20951.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20951"
        },
        {
            "cve": "CVE-2026-20959",
            "cwe": {
                "id": "CWE-79",
                "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
                    "title": "CWE-79"
                },
                {
                    "category": "description",
                    "text": "Improper input neutralization in Microsoft Office SharePoint results in cross-site scripting vulnerabilities that allow authorized attackers to perform network spoofing.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20959 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20959.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C",
                        "baseScore": 4.6,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20959"
        },
        {
            "cve": "CVE-2026-20963",
            "cwe": {
                "id": "CWE-502",
                "name": "Deserialization of Untrusted Data"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Deserialization of Untrusted Data",
                    "title": "CWE-502"
                },
                {
                    "category": "description",
                    "text": "Microsoft Office SharePoint contains a deserialization vulnerability that allows unauthorized remote code execution by processing untrusted data.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20963 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20963.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20963"
        },
        {
            "cve": "CVE-2026-20948",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                },
                {
                    "category": "description",
                    "text": "An untrusted pointer dereference vulnerability in Microsoft Office Word allows unauthorized local code execution, posing a significant security risk.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20948 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20948.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20948"
        },
        {
            "cve": "CVE-2026-20958",
            "cwe": {
                "id": "CWE-918",
                "name": "Server-Side Request Forgery (SSRF)"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Server-Side Request Forgery (SSRF)",
                    "title": "CWE-918"
                },
                {
                    "category": "description",
                    "text": "A server-side request forgery (SSRF) vulnerability in Microsoft Office SharePoint allows an authorized attacker to disclose sensitive information over a network.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20958 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20958.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C",
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20958"
        },
        {
            "cve": "CVE-2026-20953",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                },
                {
                    "category": "description",
                    "text": "A use-after-free vulnerability in Microsoft Office allows unauthorized local code execution, posing a significant security risk.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20953 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20953.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20953"
        },
        {
            "cve": "CVE-2026-20952",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                },
                {
                    "category": "description",
                    "text": "A use-after-free vulnerability in Microsoft Office allows unauthorized local code execution, posing a significant security risk.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20952 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20952.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20952"
        },
        {
            "cve": "CVE-2026-20944",
            "cwe": {
                "id": "CWE-125",
                "name": "Out-of-bounds Read"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Read",
                    "title": "CWE-125"
                },
                {
                    "category": "description",
                    "text": "An out-of-bounds read vulnerability in Microsoft Office Word allows an unauthorized attacker to execute code locally, posing a significant security risk.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20944 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20944.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20944"
        },
        {
            "cve": "CVE-2026-20946",
            "cwe": {
                "id": "CWE-125",
                "name": "Out-of-bounds Read"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Read",
                    "title": "CWE-125"
                },
                {
                    "category": "description",
                    "text": "An out-of-bounds read vulnerability in Microsoft Office Excel allows an unauthorized attacker to execute code locally, posing a significant security risk.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20946 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20946.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20946"
        },
        {
            "cve": "CVE-2026-20955",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                },
                {
                    "category": "description",
                    "text": "An untrusted pointer dereference vulnerability in Microsoft Office Excel allows an attacker to execute unauthorized local code by exploiting improper memory handling.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20955 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20955.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20955"
        },
        {
            "cve": "CVE-2026-20956",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                },
                {
                    "category": "description",
                    "text": "An untrusted pointer dereference vulnerability in Microsoft Office Excel allows an attacker to execute unauthorized local code by exploiting improper memory handling.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20956 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20956.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20956"
        },
        {
            "cve": "CVE-2026-20949",
            "notes": [
                {
                    "category": "description",
                    "text": "An improper access control vulnerability in Microsoft Office Excel allows a local unauthorized attacker to bypass a security feature, potentially compromising application security.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20949 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20949.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20949"
        },
        {
            "cve": "CVE-2026-20950",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                },
                {
                    "category": "description",
                    "text": "A vulnerability in Microsoft Office Excel, termed 'use after free,' allows unauthorized attackers to execute code locally on affected systems.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20950 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20950.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20950"
        },
        {
            "cve": "CVE-2026-20957",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                },
                {
                    "category": "other",
                    "text": "Integer Underflow (Wrap or Wraparound)",
                    "title": "CWE-191"
                },
                {
                    "category": "description",
                    "text": "An integer underflow vulnerability in Microsoft Office Excel allows unauthorized attackers to execute code locally.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6",
                    "CSAFPID-7",
                    "CSAFPID-8",
                    "CSAFPID-9",
                    "CSAFPID-10",
                    "CSAFPID-11",
                    "CSAFPID-12",
                    "CSAFPID-13",
                    "CSAFPID-14",
                    "CSAFPID-15",
                    "CSAFPID-16",
                    "CSAFPID-17",
                    "CSAFPID-18",
                    "CSAFPID-19",
                    "CSAFPID-20",
                    "CSAFPID-21",
                    "CSAFPID-22",
                    "CSAFPID-23",
                    "CSAFPID-24",
                    "CSAFPID-25",
                    "CSAFPID-26",
                    "CSAFPID-27",
                    "CSAFPID-28"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-20957 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-20957.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6",
                        "CSAFPID-7",
                        "CSAFPID-8",
                        "CSAFPID-9",
                        "CSAFPID-10",
                        "CSAFPID-11",
                        "CSAFPID-12",
                        "CSAFPID-13",
                        "CSAFPID-14",
                        "CSAFPID-15",
                        "CSAFPID-16",
                        "CSAFPID-17",
                        "CSAFPID-18",
                        "CSAFPID-19",
                        "CSAFPID-20",
                        "CSAFPID-21",
                        "CSAFPID-22",
                        "CSAFPID-23",
                        "CSAFPID-24",
                        "CSAFPID-25",
                        "CSAFPID-26",
                        "CSAFPID-27",
                        "CSAFPID-28"
                    ]
                }
            ],
            "title": "CVE-2026-20957"
        }
    ]
}