Junglewise Threat Intelligence

CVE-2026-55949: Microsoft Excel use of uninitialized resource code execution

CVE-2026-55949 · Severity: high · CVSS 7.8 · Published 2026-07-14

Executive brief

A security vulnerability exists in Microsoft Excel, a widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized changes to files, or a complete system compromise.

Technical details

A vulnerability classified as 'Use of Uninitialized Resource' (CWE-908) exists in multiple versions of Microsoft Excel and Office suites. The flaw is triggered when the application attempts to use a memory resource that has not been properly initialized. An attacker can exploit this by convincing a target user to open a malicious Excel file. Successful exploitation allows for arbitrary code execution in the context of the current user. The attack vector is local, but requires user interaction (UI:R). Microsoft has released security updates to address this issue across affected platforms including Windows and macOS.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record
  • 2026-07-14: advisory: Microsoft released the security update guide for this vulnerability

References

Related threats