Junglewise Threat Intelligence

CVE-2026-68801: Microsoft Office Excel heap-based buffer overflow

CVE-2026-68801 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel is a widely-used spreadsheet application deployed across enterprises for financial analysis, reporting, and data management. A heap-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code with the privileges of the user running Excel, potentially leading to data theft, system compromise, or lateral movement within a network.

Technical details

A heap-based buffer overflow exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when Excel processes a specially crafted spreadsheet file, causing a heap memory write to overflow and overwrite adjacent memory structures. The attack requires local file access or user interaction to open a malicious file; the vulnerability cannot be exploited remotely over the network. Successful exploitation grants code execution in the context of the user running Excel. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-08-11: disclosed

References

Related threats