Junglewise Threat Intelligence

CVE-2026-55046: Microsoft Office Excel out-of-bounds read information disclosure

CVE-2026-55046 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Excel that could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted file. This could lead to the unauthorized disclosure of private data stored in the system's memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office Excel across multiple versions, including Office 2019, 2021, 2024, and Microsoft 365 Apps. The flaw is triggered when the application fails to properly validate input, allowing a local attacker to read data outside of the intended buffer. Exploitation requires a user to open a malicious file (User Interaction: Required). Successful exploitation allows the attacker to disclose sensitive information from the process memory. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 up to Office Security Releases
  • Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 19.0.0 up to Office Security Releases
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 up to Office Security Releases
  • Microsoft Microsoft Office LTSC 2024 16.0.0 up to Office Security Releases
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats