Junglewise Threat Intelligence

CVE-2026-68808: Microsoft Office Excel out-of-bounds read

CVE-2026-68808 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel is a widely-used spreadsheet application deployed across enterprises and consumers. This vulnerability allows an attacker with local access to read sensitive information from memory that should not be accessible, potentially exposing confidential data such as formulae, cell values, or other information contained in spreadsheets.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Excel's memory handling routines. The vulnerability requires local access to the affected system and does not require authentication to trigger. An attacker can craft a malicious Office file that, when opened by a user, causes Excel to read from uninitialized or protected memory regions, disclosing information that may include previously-used data or memory contents. The attack is a classic information disclosure scenario with a reported CVSS score of 5.5 (medium severity).

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-08-11: disclosed

References

Related threats