Junglewise Threat Intelligence

CVE-2026-78515: Microsoft Excel out-of-bounds read information disclosure

CVE-2026-78515 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Excel contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information from affected systems over the network. An attacker can exploit this flaw to extract data from Excel spreadsheets or memory without requiring special credentials or user interaction. This could lead to exposure of confidential business data, customer information, or other sensitive content stored in or processed by Excel.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Excel's data parsing or processing logic. The vulnerability allows an attacker to read memory beyond intended boundaries, potentially exposing sensitive information such as private keys, credentials, or file contents. The flaw is triggered when processing a specially crafted Excel file sent over the network, with no authentication or user interaction beyond opening the malicious document. An attacker can leverage this to extract confidential data from the affected system. Microsoft has released a security update to address this vulnerability.

Affected products

  • Microsoft Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats