Junglewise Threat Intelligence

CVE-2026-50408: Microsoft Excel out-of-bounds read information disclosure

CVE-2026-50408 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Excel that could allow an unauthorized person to access sensitive information on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted Excel file. While this does not allow the attacker to take control of the system, it could lead to the exposure of private data stored in the computer's memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Excel across multiple versions, including Office 365, LTSC, and Office Online Server. The flaw is triggered when the application fails to properly validate input while reading from a memory buffer, potentially allowing an attacker to read data outside the intended memory space. Exploitation requires a local attack vector where a user is persuaded to open a malicious file (User Interaction required). Successful exploitation results in information disclosure, though it does not provide a direct path to remote code execution or data modification. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD

References

Related threats