ZeroHour

CVE-2026-78518

mass

Out-of-Bounds Read RCE in Microsoft Office Excel

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-78518 is an out-of-bounds read (rooted in improper input validation, per CWE-20/CWE-125) in Microsoft Excel, the spreadsheet component of Microsoft Office. Per the CVSS vector, an unauthenticated attacker needs no privileges but must induce user interaction — typically by getting a victim to open a specially crafted spreadsheet from email or the web — which triggers the flaw when Excel parses the malicious file. Successful exploitation yields remote code execution in the context of the current user, with high impact to confidentiality, integrity, and availability of that user's session (data theft, malware installation, or lateral movement). Any environment running Excel is potentially affected: Microsoft 365 Apps/Microsoft 365 and the perpetual Office 2016, 2019, 2021, and 2024 editions are all listed as affected products. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.9% probability of exploitation within 30 days (57th percentile), so exploitation status is none known.

What to do: Apply Microsoft's security update for Excel/Office as soon as it is available, checking the Microsoft advisory for the exact fixed build for each affected edition and update channel (Office 2016/2019/2021/2024 and Microsoft 365 Apps). Until patched, ensure Protected View and Mark-of-the-Web warnings remain enabled and consider quarantining spreadsheet attachments at the email gateway or restricting .xlsx/.xls files from untrusted sources. Verify installed Office versions against the advisory and prioritize patching this RCE even though no in-the-wild exploitation is yet known.

Affected
microsoft 365 apps
microsoft excel
microsoft 365
microsoft office 2016
microsoft office 2019
microsoft office 2021
microsoft office 2024
Estimated exposure
mass≈hundreds of millions of users (Excel ships with Microsoft 365 and perpetual Office editions) — Excel is bundled in every Microsoft 365 Apps and perpetual Office installation, so potential exposure approximates the global Office installed base — hundreds of millions of enterprise and consumer users — though only sessions in which a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-20, CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.