CVE-2026-70328: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002903 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70328?
CVE-2026-70328 has a severity rating of medium with a score of 6.5.
What does CVE-2026-70328 affect?
CVE-2026-70328 affects various versions of Microsoft Excel and Microsoft Office products, including Excel 2016 and Microsoft 365 Apps for Enterprise.
What type of vulnerability is CVE-2026-70328?
CVE-2026-70328 is categorized as an Information Disclosure vulnerability resulting from an out-of-bounds read.
How can I mitigate CVE-2026-70328?
To mitigate CVE-2026-70328, ensure that your Microsoft Excel and Office applications are updated to the latest versions.
Can CVE-2026-70328 be exploited remotely?
Yes, CVE-2026-70328 can be exploited over a network by an unauthorized attacker.