
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20957 is an integer underflow (wrap or wraparound) vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. The flaw affects a broad range of Microsoft Office products including Excel 2016, Office 2019, Office LTSC 2021/2024 (Windows x86/x64 and macOS), Microsoft 365 Apps for Enterprise, and Office Online Server (versions prior to 16.0.10417.20083). Microsoft disclosed and patched the vulnerability on January 13, 2026, as part of the January 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The vulnerability is rooted in an integer underflow (CWE-191) in Microsoft Excel's file parsing logic, which subsequently triggers a heap-based buffer overflow (CWE-122) when processing a maliciously crafted spreadsheet file. The attack vector is local (AV:L), meaning the attacker must deliver a malicious Excel file to the victim, who must then open it — requiring user interaction (UI:R) but no special privileges (PR:N). The integer underflow causes an arithmetic wraparound that results in an undersized heap buffer allocation, which is then overflowed with attacker-controlled data, potentially enabling arbitrary code execution. No public proof-of-concept exploit code has been identified as of the time of disclosure (Microsoft MSRC, Feedly).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user who opens the malicious Excel file, resulting in high confidentiality, integrity, and availability impact on the affected system. This could enable data theft, installation of malware, and lateral movement across the network if the compromised user account has broader access. The scope is limited to the affected system (S:U), but the combination of full CIA impact makes this a significant risk for enterprise environments where Office is widely deployed (Feedly, Microsoft MSRC).
.xlsx or .xls file that contains data structures designed to trigger the integer underflow in Excel's file parsing code, causing a heap buffer overflow.EXCEL.EXE) to external IP addresses or domains shortly after a file is opened; DNS queries to unusual or newly registered domains originating from Office processes.%TEMP%, %APPDATA%, or Office startup folders following the opening of an Excel document; new executable or script files created by EXCEL.EXE.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Office processes accessing sensitive system directories or registry hives not typical for normal operation.EXCEL.EXE; security logs recording new process creation events with EXCEL.EXE as the parent process.Microsoft released security updates on January 13, 2026 to address this vulnerability across all affected products. For Office Online Server, update to version 16.0.10417.20083 or later; for Office for Mac (LTSC 2021/2024), update to version 16.105.26011018 or later; for all other affected products (Microsoft 365 Apps for Enterprise, Office LTSC 2021/2024, Office 2019, Excel 2016), apply the latest updates via Microsoft's standard update channels at https://aka.ms/OfficeSecurityReleases. As a temporary workaround prior to patching, restrict users from opening Excel files received from untrusted or external sources, and consider enabling Protected View for files from the internet. User awareness training on phishing and suspicious attachments is also recommended (Microsoft MSRC, Feedly).
CVE-2026-20957 was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets. Cisco Talos, Zero Day Initiative, Qualys, CrowdStrike, Sophos, and BleepingComputer all published analyses of the January 2026 Patch Tuesday release, noting the overall volume of 114 fixes including this Excel vulnerability. No specific researcher commentary or notable social media discussion focused exclusively on this CVE was identified, consistent with its lack of active exploitation and absence of a public PoC (Talos Blog, ZDI Blog, BleepingComputer, Qualys Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."