CVE-2026-78518
massOut-of-Bounds Read RCE in Microsoft Office Excel
CVE-2026-78518 is an out-of-bounds read (rooted in improper input validation, per CWE-20/CWE-125) in Microsoft Excel, the spreadsheet component of Microsoft Office. Per the CVSS vector, an unauthenticated attacker needs no privileges but must induce user interaction — typically by getting a victim to open a specially crafted spreadsheet from email or the web — which triggers the flaw when Excel parses the malicious file. Successful exploitation yields remote code execution in the context of the current user, with high impact to confidentiality, integrity, and availability of that user's session (data theft, malware installation, or lateral movement). Any environment running Excel is potentially affected: Microsoft 365 Apps/Microsoft 365 and the perpetual Office 2016, 2019, 2021, and 2024 editions are all listed as affected products. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.9% probability of exploitation within 30 days (57th percentile), so exploitation status is none known.
What to do: Apply Microsoft's security update for Excel/Office as soon as it is available, checking the Microsoft advisory for the exact fixed build for each affected edition and update channel (Office 2016/2019/2021/2024 and Microsoft 365 Apps). Until patched, ensure Protected View and Mark-of-the-Web warnings remain enabled and consider quarantining spreadsheet attachments at the email gateway or restricting .xlsx/.xls files from untrusted sources. Verify installed Office versions against the advisory and prioritize patching this RCE even though no in-the-wild exploitation is yet known.
| microsoft 365 apps | — |
| microsoft excel | — |
| microsoft 365 | — |
| microsoft office 2016 | — |
| microsoft office 2019 | — |
| microsoft office 2021 | — |
| microsoft office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-20, CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.