Description
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. When a user opens a crafted Excel file, the buffer overflow can be triggered and code runs with the privileges of the current user. This flaw enables attackers to take control of the affected system if the user opens a malicious file.

Affected Systems

Microsoft products affected include Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version information is not provided in the advisory.

Risk and Exploitability

The CVSS score of 7.8 indicates a high impact with the possibility of arbitrary code execution. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. The primary attack vector is likely exploitation through a malicious Excel file that must be opened by the victim; unauthorized remote exploitation without user interaction is not indicated.

Generated by OpenCVE AI on July 31, 2026 at 06:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Microsoft Office update that fixes CVE-2026-56156 from the Microsoft Security Response Center.
  • For environments where the update is not yet available, restrict Excel from opening files with macro‑enabled extensions and disable legacy file types by configuring the File Open settings.
  • Educate users to avoid opening Excel files received from untrusted sources and to verify file origins before opening.

Generated by OpenCVE AI on July 31, 2026 at 06:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Title Microsoft Excel Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:26:50.221Z

Reserved: 2026-06-19T13:53:31.988Z

Link: CVE-2026-56156

cve-icon Vulnrichment

Updated: 2026-07-14T18:58:54.238Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:45:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow