Junglewise Threat Intelligence

CVE-2026-78518: Microsoft Office Excel out-of-bounds read in file parsing

CVE-2026-78518 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Excel is a spreadsheet application widely used for financial analysis and data management in businesses. An out-of-bounds read vulnerability allows attackers to execute arbitrary code remotely by sending a malicious Excel file, potentially compromising sensitive business data and enabling lateral movement across corporate networks.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when Excel processes specially crafted spreadsheet files, causing the application to read memory beyond intended boundaries. This can be exploited remotely by delivering a malicious Excel file to a user; no authentication or user interaction beyond opening the file is required. A successful exploit allows remote code execution with the privileges of the user running Excel. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats