
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21258 is an information disclosure vulnerability in Microsoft Office Excel caused by improper input validation, specifically an out-of-bounds read condition. An unauthorized local attacker can exploit this flaw by tricking a user into opening a crafted Excel file, resulting in the disclosure of sensitive memory contents. The vulnerability was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update release. Affected products include Microsoft Excel 2016 (x86/x64), Microsoft Office 2019, 2021, and 2024 (Windows and macOS), Microsoft 365 Apps for Enterprise, Office Online Server (versions before 16.0.10417.20097), and Office Long-Term Servicing Channel 2021/2024. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Feedly).
The root cause of CVE-2026-21258 is improper input validation (CWE-20) in Microsoft Office Excel's file parsing logic, leading to an out-of-bounds read condition (CWE-125). When Excel processes a specially crafted workbook file, insufficient validation of input data allows the application to read memory beyond the intended buffer boundaries, potentially exposing sensitive in-memory data. The attack vector is local, requiring no privileges but necessitating user interaction — specifically, a victim must open a malicious Excel file delivered via phishing, email attachment, or other social engineering means. No public proof-of-concept code or detailed technical write-ups have been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation of CVE-2026-21258 results in local information disclosure, with a high confidentiality impact and no effect on integrity or availability. An attacker who tricks a user into opening a malicious Excel file can read sensitive data from the affected system's memory, potentially exposing credentials, cryptographic keys, or other confidential information processed by the application. The scope is unchanged, meaning the impact is confined to the Excel process and its accessible memory, with no direct path to lateral movement or remote code execution based on currently available information (Microsoft MSRC, Feedly).
Microsoft released patches for CVE-2026-21258 on February 10, 2026, as part of the February 2026 Patch Tuesday update cycle. Administrators should apply the relevant security updates for all affected products: Microsoft Excel 2016, Microsoft Office 2019/2021/2024 (Windows and macOS), Microsoft 365 Apps for Enterprise, Office Online Server (update to version 16.0.10417.20097 or later), and Office Long-Term Servicing Channel 2021/2024. As a complementary measure, organizations should educate users to exercise caution when opening Excel files from untrusted or unknown sources, particularly those received via email (Microsoft MSRC, Feedly).
CVE-2026-21258 was covered as part of broader February 2026 Patch Tuesday roundups by several security outlets, including BleepingComputer, Qualys, Rapid7, and Sophos, though it received minimal individual attention given its medium severity and lack of active exploitation. Qualys and Rapid7 included it in their monthly patch review analyses, noting it as a lower-priority fix compared to the six zero-days addressed in the same update cycle (BleepingComputer, Qualys Blog, Rapid7 Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."