CVE-2026-68794 – Microsoft Excel Remote Code Execution Vulnerability
“A malicious Excel file can turn a routine document open into code execution, putting sensitive data and systems at risk.”
CVE-2026-68794 is a critical remote code execution vulnerability caused by a heap-based buffer overflow in Microsoft Office Excel. An attacker can send a specially crafted Office file and convince a user to open it, triggering the vulnerability locally. Successful exploitation could allow unauthorized code execution with high impact to confidentiality, integrity, and availability.
CVSS Score: 7.8.
SEVERITY: Critical.
THREAT:
An attacker could use a malicious Office file to trigger a heap-based buffer overflow and execute code on the affected system. Attack complexity is low and no privileges are required, although the targeted user must open the malicious file. The Preview Pane is not an attack vector.
EXPLOITS:
The vulnerability is not publicly disclosed and is not reported as exploited. Exploit code maturity is Unproven, and exploitation is assessed as Less Likely. No confirmed public exploit, zero-day exploitation, or proof-of-concept code is identified in the source information.
TECHNICAL SUMMARY:
CVE-2026-68794 is a heap-based buffer overflow (CWE-122) affecting Microsoft Office Excel. The attack vector is rated Local because exploitation occurs when code or content is executed from the local machine, even though an attacker may deliver the malicious document remotely. An attacker must send a specially crafted Office file and convince the victim to open it. Successful exploitation can result in arbitrary code execution and has High confidentiality, integrity, and availability impact. No privileges are required, but user interaction is required.
EXPLOITABILITY:
Affected products include Microsoft 365 Apps for Enterprise (32-bit and 64-bit), Excel 2016 (32-bit and 64-bit), Office 2019 (32-bit and 64-bit), Office 365 for Mac, Office LTSC 2021 and 2024 (32-bit and 64-bit), and Office LTSC for Mac 2021 and 2024. Exploitation requires the victim to open a malicious Office file.
BUSINESS IMPACT:
Successful exploitation could allow unauthorized code execution, potentially exposing sensitive information, compromising data integrity, and disrupting system availability. Malicious Office documents can also create a practical delivery path because exploitation can be initiated when a targeted user is persuaded to open the file.
WORKAROUND:
No workaround or mitigation is specified. An official fix is identified, so affected products should be updated through the applicable servicing method.
URGENCY:
This vulnerability is rated Critical and can result in remote code execution with High confidentiality, integrity, and availability impact. Although exploitation is assessed as Less Likely and no exploitation is reported, organizations should prioritize deployment of the official fix across affected Microsoft Office and Excel installations.
Key Details
- Affected Product
- Microsoft 365 Apps
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-122