CVE-2026-21261: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5539.1002Patch KB5002837 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.106.26020821 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20097Patch KB5002835
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21261?
CVE-2026-21261 has a medium severity rating due to potential information disclosure risks.
How do I fix CVE-2026-21261?
To fix CVE-2026-21261, ensure you apply the latest security updates from Microsoft for the affected products.
What software is affected by CVE-2026-21261?
CVE-2026-21261 affects multiple Microsoft products including Excel 2016, Office LTSC, and Microsoft 365 Apps.
What risk does CVE-2026-21261 pose to users?
CVE-2026-21261 may allow unauthorized attackers to gain access to sensitive information through an out-of-bounds read.
Is there a workaround for CVE-2026-21261?
Currently, the recommended approach to mitigate CVE-2026-21261 is to update the software to the latest version.