Junglewise Threat Intelligence

CVE-2026-55137: Microsoft Office Excel heap buffer overflow

CVE-2026-55137 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized changes to files, or a complete system compromise.

Technical details

A heap-based buffer overflow (CWE-122) exists in Microsoft Office Excel across multiple versions, including Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps. The vulnerability is triggered when the application fails to properly validate input while processing a specially crafted Excel file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local, but requires user interaction (UI:R). Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later
  • Microsoft Microsoft Office 2019 19.0.0 and later
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats