Junglewise Threat Intelligence

CVE-2026-55039: Microsoft Office Excel integer underflow code execution

CVE-2026-55039 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to run malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted Excel file. If successful, the attacker could gain the same permissions as the user, potentially leading to data theft, unauthorized system changes, or further malware installation.

Technical details

This vulnerability is classified as an integer underflow (CWE-191) which leads to a heap-based buffer overflow (CWE-122) within Microsoft Office Excel. The flaw is triggered when the application processes a specially crafted file, causing a memory corruption event. An attacker can exploit this by convincing a user to open a malicious spreadsheet, resulting in local code execution under the context of the current user. The vulnerability affects multiple versions of Microsoft Office across Windows and macOS, including LTSC and 365 variants. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
  • Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 versions prior to July 2026 updates
  • Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 versions prior to July 2026 updates
  • Microsoft Microsoft Office LTSC 2024 versions prior to July 2026 updates
  • Microsoft Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215
  • Microsoft Office Online Server versions prior to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched

References

Related threats