Junglewise Threat Intelligence

CVE-2026-45459: Microsoft Office Excel protection mechanism failure security bypass

CVE-2026-45459 · Severity: low · CVSS 3.3 · Published 2026-06-09

Technologies: Microsoft Excel. Vendors: Microsoft.

Executive brief

A security bypass vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw to circumvent built-in security protections, potentially gaining unauthorized access to limited information on a user's local system. Successful exploitation requires a user to interact with a specially crafted file, which could lead to a minor breach of data confidentiality.

Technical details

A protection mechanism failure (CWE-693) exists in Microsoft Office Excel. The vulnerability allows an unauthorized attacker to bypass local security features, though the impact is limited to a low-level breach of confidentiality (C:L). The attack vector is local and requires user interaction, typically involving a victim opening a malicious file. According to the CVSS vector, the exploit does not require elevated privileges and has no impact on system integrity or availability. Microsoft has released information regarding this vulnerability in their June 2026 update cycle.

Affected products

  • Microsoft Excel

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Microsoft MSRC advisory published

References

Related threats