CVE-2026-26107

7.8

Microsoft · Office Excel

A use after free vulnerability in Microsoft Office Excel permits an unauthorized attacker to execute arbitrary code locally on the target system.

Executive summary

A use after free vulnerability in Microsoft Office Excel exposes users to potential arbitrary code execution via malicious files.

Vulnerability

This is a use after free flaw (CWE-416) within Microsoft Office Excel that can be triggered by an unauthorized attacker. Successful exploitation requires the user to open a specially crafted file, leading to potential local code execution.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity level. Successful exploitation allows an attacker to gain the same privileges as the local user, which could result in full system compromise, data exfiltration, or the installation of malicious software on corporate endpoints.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official security update guide immediately to patch the affected Excel versions.

Proactive Monitoring: Monitor endpoint logs for abnormal application crashes or unexpected child processes spawned by the Excel application, which may indicate exploitation attempts.

Compensating Controls: Implement strict email filtering and endpoint protection policies to block untrusted or suspicious Office documents from being opened by end users.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for code execution, organizations should prioritize the deployment of Microsoft security patches across all affected Excel installations. Ensure that automated update mechanisms are functioning correctly to minimize the window of exposure for end users.

More Microsoft CVEs

Sources