Junglewise Threat Intelligence

CVE-2026-54988: Microsoft Excel out-of-bounds read information disclosure

CVE-2026-54988 · Severity: medium · CVSS 6.1 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Excel is a widely used spreadsheet application for data analysis and business reporting. A security vulnerability has been identified that could allow an attacker to access sensitive information or cause the application to crash if a user opens a specially crafted file. This could lead to the exposure of private data or a disruption in business operations for users working with Excel documents.

Technical details

This vulnerability is classified as an out-of-bounds read (CWE-125) within Microsoft Office Excel. The flaw occurs when the application reads data past the end of the intended buffer while processing a malicious file. An attacker can exploit this by convincing a user to open a specially crafted Excel document (requiring user interaction). Successful exploitation can lead to the disclosure of sensitive information from the application's memory or a denial-of-service condition (application crash). The vulnerability affects multiple versions of Excel across Windows and macOS, as well as Office Online Server.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD

References

Related threats