
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20946 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021, Office LTSC 2024, Microsoft 365 Apps for Enterprise, and Office for Mac (2021 and 2024 versions). It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), occurring within Microsoft Excel's file parsing logic. An attacker crafts a malicious Excel spreadsheet that, when opened by a victim, triggers an out-of-bounds memory read condition that can be leveraged to achieve local code execution. Exploitation requires user interaction — specifically, a user must open a specially crafted Excel file — and no elevated privileges are required on the part of the attacker. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation results in arbitrary code execution in the context of the logged-in user on the local system, with high impact to confidentiality, integrity, and availability. An attacker could steal sensitive data, modify or delete files, install malware, or disrupt system operations. The attack vector is local and requires user interaction, limiting remote mass exploitation, but the vulnerability remains significant in targeted phishing or spear-phishing scenarios where malicious Excel files are delivered via email or other channels (Microsoft MSRC, Feedly).
.xlsx or .xls file that triggers an out-of-bounds read in Excel's file parsing engine when processed..xlsx/.xls files received via email or downloaded from untrusted sources; new or modified files in user profile directories following Excel usage.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected network connections.EXCEL.EXE to unknown or suspicious external IP addresses or domains shortly after a file is opened.EXCEL.EXE; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps or %TEMP% related to Excel.Microsoft released a security patch on January 13, 2026, addressing this vulnerability. Affected users should apply the update immediately via Windows Update or the Microsoft Update Catalog; specific fixed build numbers include Microsoft Excel 2016 version 16.0.5535.1000 and Office for Mac 2021/2024 version 16.105.26011018 (Microsoft MSRC). As interim mitigations, organizations should educate users to avoid opening Excel files from untrusted sources, consider enabling Protected View for Office files from the internet, and implement application whitelisting. Disabling macros in Excel where not required for business operations can also reduce the attack surface.
CVE-2026-20946 was covered as part of broader reporting on Microsoft's January 2026 Patch Tuesday, which addressed 114 vulnerabilities including 3 zero-days. Security outlets including BleepingComputer, CyberSecurityNews, and GBHackers reported on the patch release, though CVE-2026-20946 was not individually highlighted as a critical concern given the absence of active exploitation (BleepingComputer, CyberSecurityNews). The Zero Day Initiative (ZDI) published its January 2026 Security Update Review, which covered the broader patch set (ZDI Blog). Sophos and Lansweeper also published Patch Tuesday summaries referencing the update (Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."