
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20950 is a use-after-free vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Excel 2016, Office 2019, Office LTSC 2021 and 2024, Microsoft 365 Apps for Enterprise, Office Online Server (before 16.0.10417.20083), and Office for Mac 2021 and 2024. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), meaning Excel improperly accesses memory after it has been freed during the processing of a specially crafted Excel file. An attacker exploits this condition by enticing a user to open a malicious Excel document, triggering the use-after-free to gain code execution in the context of the logged-in user. No privileges are required on the part of the attacker, but user interaction (opening the file) is a prerequisite. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation grants an attacker arbitrary code execution with the privileges of the victim user, resulting in high impact to confidentiality, integrity, and availability. An attacker could access sensitive data, modify or delete files, install malware, or use the compromised system as a pivot point for lateral movement within a network. The scope is limited to the local system context of the user who opens the malicious file (Microsoft MSRC, Feedly).
EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, curl.exe) shortly after a user opens an Excel file.EXCEL.EXE or its child processes to external IP addresses or domains not associated with Microsoft services.%TEMP%, %APPDATA%) created by Excel processes; unexpected scripts or executables dropped alongside or after opening an Excel file.EXCEL.EXE; Security logs recording new process creation events parented to Excel with suspicious command-line arguments.Microsoft released security patches on January 13, 2026, addressing this vulnerability across all affected products. Administrators should apply updates to Excel 2016 (to build 16.0.5535.1000 or later), Office Online Server (to 16.0.10417.20083 or later), Office LTSC for Mac 2021 (to 16.105.26011018 or later), and Office LTSC for Mac 2024 (to 16.105.26011018 or later); Microsoft 365 Apps for Enterprise and Office 2019/2021/2024 should be updated via the standard Office update mechanism. As interim mitigations, organizations should restrict users from opening Excel files from untrusted sources, implement email filtering to block unsolicited Office attachments, and consider enabling Protected View or Attack Surface Reduction (ASR) rules in Microsoft Defender to limit Office macro and file execution risks (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Zero Day Initiative (ZDI), Sophos, Lansweeper, and Petri, which collectively noted the patch addressed 114 flaws including 3 zero-days (CVE-2026-20950 was not among the zero-days). Flare.io published a post-Patch Tuesday intelligence report examining cybercrime activity following the January 2026 updates. Community discussion on platforms such as Mastodon (infosec.exchange) and forums like ElevenForum noted the update without significant alarm specific to this CVE, consistent with its lack of active exploitation (BleepingComputer, ZDI, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."