publisher vulnerabilities
CVEs whose affected-version data names the publisher package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-81385High· 8.8Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
▾ Twilightmicrosoft · 365_appsEPSS 1.0%via NVD
CVE-2026-69742High· 8.8Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD