CVE-2026-20946
vulnerability analysis and mitigation

Overview

CVE-2026-20946 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021, Office LTSC 2024, Microsoft 365 Apps for Enterprise, and Office for Mac (2021 and 2024 versions). It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), occurring within Microsoft Excel's file parsing logic. An attacker crafts a malicious Excel spreadsheet that, when opened by a victim, triggers an out-of-bounds memory read condition that can be leveraged to achieve local code execution. Exploitation requires user interaction — specifically, a user must open a specially crafted Excel file — and no elevated privileges are required on the part of the attacker. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in arbitrary code execution in the context of the logged-in user on the local system, with high impact to confidentiality, integrity, and availability. An attacker could steal sensitive data, modify or delete files, install malware, or disrupt system operations. The attack vector is local and requires user interaction, limiting remote mass exploitation, but the vulnerability remains significant in targeted phishing or spear-phishing scenarios where malicious Excel files are delivered via email or other channels (Microsoft MSRC, Feedly).

Exploitation steps

  1. Craft a malicious Excel file: Create a specially crafted .xlsx or .xls file that triggers an out-of-bounds read in Excel's file parsing engine when processed.
  2. Deliver the payload: Distribute the malicious file to the target via phishing email, malicious download link, or other social engineering methods.
  3. Induce user interaction: Convince the target user to open the malicious Excel file using a vulnerable version of Microsoft Excel (2016, 2019, 2021, 2024, or Microsoft 365 Apps for Enterprise).
  4. Trigger the vulnerability: Upon opening, Excel's parser reads beyond the bounds of an allocated memory buffer, potentially exposing or corrupting adjacent memory.
  5. Achieve code execution: The out-of-bounds read condition is exploited to redirect execution flow, resulting in arbitrary code running under the privileges of the current user (Microsoft MSRC).

Indicators of compromise

  • File System: Unexpected or suspicious .xlsx/.xls files received via email or downloaded from untrusted sources; new or modified files in user profile directories following Excel usage.
  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected network connections.
  • Network: Outbound connections from EXCEL.EXE to unknown or suspicious external IP addresses or domains shortly after a file is opened.
  • Logs: Windows Event Logs showing application crashes or faults in EXCEL.EXE; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps or %TEMP% related to Excel.

Mitigation and workarounds

Microsoft released a security patch on January 13, 2026, addressing this vulnerability. Affected users should apply the update immediately via Windows Update or the Microsoft Update Catalog; specific fixed build numbers include Microsoft Excel 2016 version 16.0.5535.1000 and Office for Mac 2021/2024 version 16.105.26011018 (Microsoft MSRC). As interim mitigations, organizations should educate users to avoid opening Excel files from untrusted sources, consider enabling Protected View for Office files from the internet, and implement application whitelisting. Disabling macros in Excel where not required for business operations can also reduce the attack surface.

Community reactions

CVE-2026-20946 was covered as part of broader reporting on Microsoft's January 2026 Patch Tuesday, which addressed 114 vulnerabilities including 3 zero-days. Security outlets including BleepingComputer, CyberSecurityNews, and GBHackers reported on the patch release, though CVE-2026-20946 was not individually highlighted as a critical concern given the absence of active exploitation (BleepingComputer, CyberSecurityNews). The Zero Day Initiative (ZDI) published its January 2026 Security Update Review, which covered the broader patch set (ZDI Blog). Sophos and Lansweeper also published Patch Tuesday summaries referencing the update (Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management