CVE-2026-68802: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002903 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002884
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68802?
CVE-2026-68802 has a medium severity rating of 5.5.
How do I fix CVE-2026-68802?
To mitigate CVE-2026-68802, apply the latest security updates provided by Microsoft for affected versions of Excel and Office.
What type of vulnerability is CVE-2026-68802?
CVE-2026-68802 is classified as an information disclosure vulnerability due to an out-of-bounds read in Microsoft Excel.
Which software is affected by CVE-2026-68802?
CVE-2026-68802 affects Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, and other versions of Microsoft Office, including 2019, 2021, 2024, and 365 for Mac.
What can an attacker achieve by exploiting CVE-2026-68802?
An attacker can exploit CVE-2026-68802 to disclose sensitive information locally without authentication.