Junglewise Threat Intelligence

CVE-2026-68817: Microsoft Office Excel stack-based buffer overflow

CVE-2026-68817 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel contains a stack-based buffer overflow vulnerability that allows an attacker to execute arbitrary code locally on affected systems. An attacker with local access could exploit this flaw to gain control of the system and compromise sensitive data or business operations.

Technical details

A stack-based buffer overflow vulnerability exists in Microsoft Office Excel due to insufficient input validation when processing specially crafted spreadsheet files. The vulnerability requires local access to the affected system and can be triggered by opening a malicious Excel file. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Excel. Microsoft has released security patches to remediate this issue.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-08-11: disclosed

References

Related threats