Microsoft Excel

32 known vulnerabilities in Microsoft Excel, 2 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2021-42292 CVSS 7.8 high · actively exploited Microsoft Excel Security Feature Bypass
  • CVE-2019-1297 CVSS 8.8 high · actively exploited Microsoft Excel Remote Code Execution Vulnerability

Latest vulnerabilities

  • CVE-2026-85875 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81960 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81959 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81958 CVSS 5.5 medium Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81957 CVSS 7.8 high Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81956 CVSS 7.8 high Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81954 CVSS 7.8 high Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81953 CVSS 7.8 high Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81951 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81950 CVSS 7.8 high Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81949 CVSS 7.8 high Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81948 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81947 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81401 CVSS 5.5 medium Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose…
  • CVE-2026-81400 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81399 CVSS 5.5 medium Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81398 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81397 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81396 CVSS 7.8 high Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81395 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81394 CVSS 5.5 medium Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to…
  • CVE-2026-81393 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81392 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81391 CVSS 5.5 medium Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81390 CVSS 5.5 medium Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
  • CVE-2026-81389 CVSS 7.0 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81388 CVSS 7.8 high Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-81387 CVSS 5.5 medium Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to…
  • CVE-2026-81386 CVSS 7.8 high Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
  • CVE-2026-78518 CVSS 8.8 high Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.