Junglewise Threat Intelligence

CVE-2026-55131: Microsoft Excel heap buffer overflow code execution

CVE-2026-55131 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC 2021, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Excel could allow an attacker to execute malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted Excel file. Successful exploitation could lead to a full compromise of the user's data and local system access.

Technical details

A heap-based buffer overflow (CWE-122) exists in Microsoft Excel across multiple versions, including Office 2016, 2019, 2021, and Microsoft 365 Apps. The vulnerability is triggered when the application processes a malformed file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious spreadsheet, resulting in arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise >= 16.0.1
  • Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 >= 19.0.0
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 >= 16.0.1
  • Microsoft Microsoft Office LTSC 2024 >= 16.0.0
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record.
  • 2026-07-14: advisory: Microsoft released security update details.

References

Related threats