CVE-2026-68799: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Other sources
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002903 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68799?
The severity of CVE-2026-68799 is rated as medium with a score of 5.5.
How does CVE-2026-68799 impact Microsoft Excel?
CVE-2026-68799 allows an unauthorized attacker to disclose information locally due to the use of uninitialized resources in Microsoft Excel.
Which versions of Microsoft Excel are affected by CVE-2026-68799?
CVE-2026-68799 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, and Microsoft Office LTSC versions for both 32-bit and 64-bit editions.
How can I mitigate the risk of CVE-2026-68799?
To mitigate the risk of CVE-2026-68799, ensure that you apply the latest security updates provided for the affected Microsoft Excel versions.
Is there a workaround for CVE-2026-68799?
Currently, there are no specific workarounds for CVE-2026-68799, so keeping software updated is critical.