Junglewise Threat Intelligence

CVE-2026-55031: Microsoft Excel out-of-bounds read code execution

CVE-2026-55031 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Excel is a widely used spreadsheet application for data analysis and reporting. A security vulnerability has been identified that could allow an attacker to take control of a user's computer if the user is tricked into opening a specially crafted Excel file. This could lead to the theft of sensitive data, installation of malware, or disruption of business operations.

Technical details

A vulnerability classified as an out-of-bounds read (CWE-125) exists in Microsoft Excel. The flaw is triggered when the application fails to properly validate memory boundaries while parsing a maliciously crafted spreadsheet file. An attacker can exploit this by convincing a user to open a compromised file, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), and affects multiple versions of Office across Windows and macOS, as well as Office Online Server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft Excel 2016 < 16.0.5561.1001
  • Microsoft Microsoft 365 Apps for Enterprise All versions prior to July 2026 update
  • Microsoft Microsoft Office 2019 All versions prior to July 2026 update
  • Microsoft Microsoft Office LTSC 2021 All versions prior to July 2026 update
  • Microsoft Microsoft Office LTSC 2024 All versions prior to July 2026 update
  • Microsoft Microsoft Office 365 for Mac < 16.111.26071215
  • Microsoft Office Online Server < 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats