Junglewise Threat Intelligence

CVE-2026-68807: Microsoft Office Excel heap-based buffer overflow

CVE-2026-68807 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel is a widely-used spreadsheet application for business data analysis and reporting. A heap-based buffer overflow vulnerability could allow an attacker to execute arbitrary code on a user's computer if a malicious Excel file is opened, potentially leading to data theft, system compromise, or installation of ransomware.

Technical details

This is a heap-based buffer overflow vulnerability in Microsoft Office Excel. The vulnerability is triggered by processing a specially crafted Excel file, requiring user interaction (opening the file) to exploit. An attacker with no special privileges can achieve arbitrary code execution in the context of the user running Excel. The attack vector is local; the affected user must open a malicious Excel document. A patch is expected to be available through Microsoft's security update process.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-08-11: disclosed

References

Related threats