← Back

CVE-2026-21259

nvd nist
Published: Feb 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.

Affected (11)

5 products
365 Apps
Excel
Office
Office Online Server
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
Microsoft
Version 2016
Version 2016
Microsoft
Version 2019
Version 2019
Microsoft
Version 2021
Version 2021
Version 2024
Version 2024
Before 16.0.10417.20097

References (1)

Timeline

No history available yet.