Out-of-bounds read in Microsoft Office for macOS and Microsoft Excel - CVE-2026-70328
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in Microsoft Office Excel when parsing a specially crafted file. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.
The Preview Pane is not an attack vector. Successful exploitation could allow reading portions of process memory.
Affected software
Microsoft Excel
How to mitigate CVE-2026-70328
Microsoft Excel - update to 16.0.5565.1001