Junglewise Threat Intelligence

CVE-2026-68800: Microsoft Office Excel heap-based buffer overflow

CVE-2026-68800 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel contains a heap-based buffer overflow vulnerability that allows a locally-authenticated attacker to execute arbitrary code on an affected system. This could enable an attacker to gain full control of a user's computer, steal sensitive data, or distribute malware within an organization.

Technical details

The vulnerability is a heap-based buffer overflow in Microsoft Office Excel that permits an attacker with local access and the ability to open a specially-crafted Excel file to achieve arbitrary code execution. The flaw resides in memory management within Excel's file parsing logic. An attacker would need to trick a user into opening a malicious Excel document, after which the overflow condition could be triggered to corrupt heap memory and redirect execution to attacker-controlled code. Patches are expected to be available through Microsoft's regular security updates.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-08-11: disclosed

References

Related threats