Junglewise Threat Intelligence

CVE-2026-58618: Microsoft Excel heap buffer overflow remote code execution

CVE-2026-58618 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Excel, a widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, installation of malicious software, or disruption of business operations.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in Microsoft Office Excel. The flaw is triggered when the application fails to properly validate input while processing a specially crafted Excel file. An attacker can exploit this by convincing a target user to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local, but requires user interaction (UI:R). Affected products include various versions of Microsoft Office, Office LTSC, and Office Online Server across Windows and macOS platforms. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Excel 2016 < 16.0.5561.1001
  • Microsoft Office 2019 All versions
  • Microsoft Office LTSC 2021 All versions
  • Microsoft Office LTSC 2024 All versions
  • Microsoft 365 Apps for Enterprise All versions
  • Microsoft Office 365 for Mac < 16.111.26071215
  • Microsoft Office Online Server < 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats