CVE-2026-50408
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Read in Microsoft Office Excel

Vulnerability report for CVE-2026-50408, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
microsoft 365_apps *
microsoft 365_apps *
microsoft excel 2016
microsoft excel 2016
microsoft office_2019 *
microsoft office_2019 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_online_server to 16.0.10417.20175 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50408 is an out-of-bounds read vulnerability in Microsoft Office Excel. This flaw allows an unauthorized attacker to access and disclose sensitive information locally on the affected system.

An out-of-bounds read occurs when the software reads data beyond the intended buffer or memory boundary. In this case, Excel improperly handles certain inputs, enabling an attacker to read memory locations that should not be accessible, potentially exposing confidential data.

  • The vulnerability is classified with a CVSS v3.1 BaseScore of 5.5, indicating a medium severity level.
  • The CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, meaning it requires local access (AV:L), low attack complexity (AC:L), no privileges (PR:N), user interaction (UI:R), and has a high impact on confidentiality (C:H) but no impact on integrity or availability.
Impact Analysis

This vulnerability can impact you in several ways if you use Microsoft Office Excel on an affected system.

  • An attacker could exploit this flaw to access sensitive information stored in memory, such as passwords, financial data, or other confidential documents.
  • Since the attack requires local access, the risk is higher in environments where multiple users share the same machine or where an attacker has physical or remote access to a system.
  • The vulnerability does not allow for remote code execution or privilege escalation, but the disclosed information could be used for further attacks or identity theft.

To mitigate the risk, ensure you apply the latest security updates from Microsoft as soon as they are available.

Compliance Impact

This vulnerability could affect compliance with several common standards and regulations, depending on the nature of the data being processed or stored.

  • GDPR: If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a data breach under GDPR. Organizations may face fines or penalties if they fail to protect personal data adequately or do not report the breach within the required timeframe.
  • HIPAA: For organizations handling protected health information (PHI) in the U.S., this vulnerability could result in unauthorized disclosure of PHI. This would constitute a breach under HIPAA, requiring notification and potentially leading to penalties if proper safeguards were not in place.
  • Other standards like PCI DSS (for payment card data) or industry-specific regulations may also be impacted if the disclosed information includes sensitive financial or proprietary data.

To maintain compliance, organizations should promptly apply security patches, monitor for signs of exploitation, and ensure that any potential data breaches are reported in accordance with applicable regulations.

Mitigation Strategies

Apply the latest security updates provided by Microsoft for Microsoft Office Excel. This vulnerability is addressed in the patches listed in the Microsoft Update Guide for CVE-2026-50408.

  • Check for available updates via Windows Update or Microsoft Update Catalog.
  • Ensure all systems running Microsoft Office Excel are updated to the latest patched version.
  • Monitor the Microsoft Security Response Center (MSRC) for any additional guidance or workarounds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50408. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart