CVE-2026-55898: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002886 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002884
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55898?
CVE-2026-55898 has a severity rating of high with a score of 7.1.
How does CVE-2026-55898 affect Microsoft Excel?
CVE-2026-55898 allows an unauthorized attacker to perform an out-of-bounds read that discloses information locally.
How do I fix CVE-2026-55898?
To fix CVE-2026-55898, ensure that you have installed the latest security updates from Microsoft for affected versions of Excel.
Which software versions are vulnerable to CVE-2026-55898?
CVE-2026-55898 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office Online Server, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
What is the potential impact of CVE-2026-55898?
The potential impact of CVE-2026-55898 includes unauthorized information disclosure which can compromise sensitive data.