CVE-2026-26107
7.8Microsoft · Office Excel
A use after free vulnerability in Microsoft Office Excel permits an unauthorized attacker to execute arbitrary code locally on the target system.
Executive summary
A use after free vulnerability in Microsoft Office Excel exposes users to potential arbitrary code execution via malicious files.
Vulnerability
This is a use after free flaw (CWE-416) within Microsoft Office Excel that can be triggered by an unauthorized attacker. Successful exploitation requires the user to open a specially crafted file, leading to potential local code execution.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity level. Successful exploitation allows an attacker to gain the same privileges as the local user, which could result in full system compromise, data exfiltration, or the installation of malicious software on corporate endpoints.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official security update guide immediately to patch the affected Excel versions.
Proactive Monitoring: Monitor endpoint logs for abnormal application crashes or unexpected child processes spawned by the Excel application, which may indicate exploitation attempts.
Compensating Controls: Implement strict email filtering and endpoint protection policies to block untrusted or suspicious Office documents from being opened by end users.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for code execution, organizations should prioritize the deployment of Microsoft security patches across all affected Excel installations. Ensure that automated update mechanisms are functioning correctly to minimize the window of exposure for end users.
More Microsoft CVEs
Sources
- Microsoft Excel Remote Code Execution Vulnerability Vendor advisory