Junglewise Threat Intelligence

CVE-2026-55036: Microsoft Excel buffer over-read code execution

CVE-2026-55036 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Excel, the widely used spreadsheet application. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive data, installation of malware, or full control over the affected workstation.

Technical details

A buffer over-read vulnerability (CWE-126) exists in Microsoft Office Excel across multiple versions, including Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps. The flaw is triggered when the application fails to properly validate input while reading from a memory buffer, which can be exploited via a specially crafted Excel file. While the attack vector is local, it requires user interaction (UI:R) to open the malicious document. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise < 16.0.1
  • Microsoft Microsoft Excel 2016 < 16.0.5561.1001
  • Microsoft Microsoft Office 2019 All versions
  • Microsoft Microsoft Office 365 for Mac < 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 All versions
  • Microsoft Microsoft Office LTSC 2024 All versions
  • Microsoft Microsoft Office LTSC for Mac 2021 < 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 < 16.111.26071215
  • Microsoft Office Online Server < 16.0.10417.20175

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed

References

Related threats