Junglewise Threat Intelligence

CVE-2026-40362: Microsoft Office Excel heap buffer overflow

CVE-2026-40362 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Office Excel, Microsoft Excel. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. If a user opens a specially crafted malicious file, an attacker could gain the ability to run unauthorized commands or software on the victim's computer. This could lead to a full system compromise, data theft, or the installation of malware.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists within Microsoft Office Excel. The flaw is triggered when the application fails to properly validate or bounds-check data while processing a specially crafted Excel file. An attacker can exploit this by tricking a user into opening a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), and carries a CVSS base score of 7.8 due to the high impact on confidentiality, integrity, and availability.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Published by Microsoft and NVD

References

Related threats