Junglewise Threat Intelligence

CVE-2026-68811: Microsoft Office Excel type confusion vulnerability

CVE-2026-68811 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel contains a type confusion vulnerability that allows an attacker to execute arbitrary code on a user's computer by opening a maliciously crafted spreadsheet. This could result in complete system compromise, data theft, or installation of malware without requiring administrative privileges.

Technical details

A type confusion vulnerability exists in Microsoft Office Excel where the application incorrectly handles resource access with incompatible types, allowing memory corruption. An attacker can exploit this vulnerability by crafting a malicious Excel file that, when opened by a user, triggers the type confusion condition. The vulnerability requires user interaction (opening a file) and results in arbitrary code execution with the privileges of the user running Excel. No patch information is currently available in the provided advisory.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-08-11: disclosed

References

Related threats