CVE-2026-55138: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Other sources
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002886 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002884 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55138?
The severity of CVE-2026-55138 is rated as medium with a score of 5.5.
How do I fix CVE-2026-55138?
To fix CVE-2026-55138, ensure that your version of Microsoft Excel and related applications are updated to the latest security patches provided by Microsoft.
What applications are affected by CVE-2026-55138?
CVE-2026-55138 affects Microsoft Excel, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
What type of vulnerability is CVE-2026-55138?
CVE-2026-55138 is an information disclosure vulnerability caused by an untrusted pointer dereference in Microsoft Office Excel.
What can an attacker achieve with CVE-2026-55138?
An unauthorized attacker exploiting CVE-2026-55138 can disclose information locally from affected versions of Microsoft Excel.