Junglewise Threat Intelligence

CVE-2026-55122: Microsoft Excel out-of-bounds read information disclosure

CVE-2026-55122 · Severity: high · CVSS 7.1 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. If a user is tricked into opening a specially crafted file, an attacker could gain access to sensitive information stored in the computer's memory or cause the application to crash. This could lead to the exposure of confidential data or disrupt business operations by making the software unavailable.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Excel due to improper validation of data when parsing specially crafted files. An attacker can exploit this by convincing a user to open a malicious Excel file, leading to the disclosure of sensitive information from the process memory or an application crash (denial of service). The attack vector is local, but requires user interaction (UI:R) to trigger the flaw. Affected products include various versions of Microsoft Office, Excel 2016, and Office Online Server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
  • Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 versions prior to July 2026 updates
  • Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 / 2024 versions prior to July 2026 updates
  • Microsoft Office Online Server versions prior to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record.
  • 2026-07-14: advisory: Microsoft released the security update guide for this vulnerability.

References

Related threats