Description
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow in Microsoft Office Excel permits a local attacker with access to an affected system to execute arbitrary code on the device. The flaw arises when Excel processes data that exceeds the allocated memory buffer, allowing the attacker to control program flow and run malicious payloads. This flaw reflects a CWE‑122 heap‑based buffer overflow. Because the vulnerability grants code execution at the current user level, it can lead to full system compromise, data exfiltration, or the installation of persistent malware.

Affected Systems

The affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All listed editions of Windows and macOS Office are potentially vulnerable; administrators should verify that the latest security updates are installed on affected systems.

Risk and Exploitability

With a CVSS score of 7.8, the vulnerability is considered high severity. An EPSS score of < 1% indicates a very low, yet non‑zero, likelihood that this flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits. Still, local code execution poses a serious threat in environments where users can open potentially malicious files. Prompt patching is therefore essential to mitigate even a low‑probability risk.

Generated by OpenCVE AI on August 12, 2026 at 16:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office security update that addresses CVE-2026-68798 for all affected 365 Apps, Office 365, and LTSC editions on both Windows and macOS.
  • Configure the Office applications to treat untrusted files as safe, such as enabling the protected view for files originating from the internet or from potentially unsafe locations, based on common security guidance.
  • Enable automatic updates for Office to ensure future patches are applied without manual intervention, based on standard industry practice.

Generated by OpenCVE AI on August 12, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Title Microsoft Excel Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:51.462Z

Reserved: 2026-07-31T16:33:08.216Z

Link: CVE-2026-68798

cve-icon Vulnrichment

Updated: 2026-08-11T18:11:06.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:03.400

Modified: 2026-08-12T15:55:51.387

Link: CVE-2026-68798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:30:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow