Junglewise Threat Intelligence

CVE-2026-55948: Microsoft Office Excel use after free code execution

CVE-2026-55948 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized changes to files, or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in Microsoft Office Excel (CWE-416). The flaw is triggered when the application attempts to access memory that has already been freed, typically during the processing of a maliciously crafted Excel file. While the attack vector is classified as local, it requires user interaction (UI:R), meaning an attacker must convince a target to open a booby-trapped document. Successful exploitation can lead to arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across various versions of Office, including LTSC and Microsoft 365 Apps.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
  • Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 versions prior to July 2026 updates
  • Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 versions prior to July 2026 updates
  • Microsoft Microsoft Office LTSC 2024 versions prior to July 2026 updates
  • Microsoft Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215
  • Microsoft Office Online Server versions prior to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats