CVE-2026-55058
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Read in Microsoft Office Excel

Vulnerability report for CVE-2026-55058, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: Microsoft Corporation

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
microsoft 365_apps *
microsoft 365_apps *
microsoft excel 2016
microsoft excel 2016
microsoft office_2019 *
microsoft office_2019 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_online_server to 16.0.10417.20175 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55058 is an out-of-bounds read vulnerability in Microsoft Office Excel. This flaw allows an unauthorized attacker to execute code locally on a victim's system.

An out-of-bounds read occurs when a program reads data beyond the intended memory boundary. In this case, the vulnerability in Excel could be exploited by an attacker to access sensitive information or execute arbitrary code on the affected system.

The CVSS v3.1 score for this vulnerability is 7.8, indicating a high severity level. The vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H means the attack requires local access, has low attack complexity, no privileges are needed, but user interaction is required. The impact includes high confidentiality, integrity, and availability risks.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-55058 on a network or system.

To detect this vulnerability, you may need to check for the installation of affected Microsoft Office Excel versions or apply Microsoft-provided detection tools or updates. Refer to the official Microsoft security update guide for potential detection guidance.

Impact Analysis

This vulnerability can impact you in several ways if you use Microsoft Office Excel and open a maliciously crafted file.

  • An attacker could execute arbitrary code on your system, potentially taking full control of it.
  • Sensitive data stored on your system could be accessed, stolen, or modified by the attacker.
  • The attacker could install malware, create new user accounts, or perform other malicious actions on your system.

Since the vulnerability requires user interaction (e.g., opening a file), you are at risk if you receive and open a specially crafted Excel file from an untrusted source.

Compliance Impact

This vulnerability could affect compliance with several common standards and regulations, depending on how it is exploited and the nature of the data involved.

  • GDPR: If the vulnerability leads to unauthorized access or exfiltration of personal data of EU citizens, it could result in a data breach. Organizations must report such breaches within 72 hours and may face significant fines if they fail to protect personal data adequately.
  • HIPAA: For organizations handling protected health information (PHI), exploitation of this vulnerability could lead to unauthorized access to PHI. This would constitute a breach under HIPAA, requiring notification and potentially resulting in penalties if proper safeguards were not in place.
  • Other standards like ISO 27001 or NIST frameworks require organizations to manage vulnerabilities and protect systems from unauthorized access. Failure to patch or mitigate this vulnerability could result in non-compliance with these standards.

Organizations should assess the risk posed by this vulnerability and take appropriate measures, such as applying patches or implementing workarounds, to maintain compliance with relevant regulations.

Mitigation Strategies

Apply the security update provided by Microsoft to address CVE-2026-55058. This update will patch the out-of-bounds read vulnerability in Microsoft Office Excel.

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-55058 to download and install the latest patch.
  • Ensure all systems running Microsoft Office Excel are updated to the latest secure version.
  • Monitor Microsoft’s official communications for any additional mitigation steps or workarounds if a patch is not immediately available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart