CVE-2026-26109

8.4

Microsoft · Office Excel

An out-of-bounds read vulnerability in Microsoft Office Excel may allow an unauthorized attacker to achieve local code execution.

Executive summary

A critical out-of-bounds read vulnerability in Microsoft Office Excel poses a significant risk for local code execution on affected systems.

Vulnerability

The vulnerability is an out-of-bounds read (CWE-125) occurring within the Excel application, which can be triggered by an unauthorized attacker to execute code locally.

Business impact

The vulnerability carries a CVSS score of 8.4, which indicates a high severity level. Successful exploitation could lead to total compromise of the affected host, including unauthorized data access, system integrity loss, and potential lateral movement within the corporate network.

Remediation

Immediate Action: Administrators must apply the latest security updates provided by Microsoft via the official update guide at https://aka.ms/OfficeSecurityReleases.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution originating from the Excel application.

Compensating Controls: Ensure that Office macro security settings are configured to high, and consider implementing attack surface reduction rules to prevent Office applications from creating child processes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS severity and the potential for code execution, organizations should prioritize the deployment of the vendor-supplied patches across all instances of Excel. Failure to update may expose systems to local exploitation, leading to full system compromise.

More Microsoft CVEs

Sources