Junglewise Threat Intelligence

CVE-2026-85875: Microsoft Office Excel out-of-bounds read

CVE-2026-85875 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel contains an out-of-bounds read vulnerability that allows an attacker with local access to read sensitive information from the application's memory. An attacker could exploit this to disclose confidential data such as spreadsheet contents, credentials, or other sensitive information stored in memory.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Office Excel that permits disclosure of information. The flaw allows an attacker with local access to the system to read memory beyond intended boundaries, potentially exposing sensitive data. Exploitation requires local access to the affected system. The out-of-bounds read can be triggered to leak arbitrary memory contents from the Excel process.

Affected products

  • Microsoft Office Excel <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats