
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21259 is a heap-based buffer overflow vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to elevate privileges on the affected system. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday release, it affects Microsoft 365 Apps for Enterprise (x64/x86), Excel 2016 (x64/x86), Office 2019 (x64/x86), Office 2021 LTSC (x64/x86), Office 2024 LTSC (x64/x86), and Office Online Server (versions before 16.0.10417.20097). It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified under CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), and is associated with CAPEC-92 (Forced Integer Overflow). Exploitation requires user interaction — specifically, a victim must open a specially crafted malicious Excel file, after which the heap-based buffer overflow is triggered during file parsing, enabling local privilege escalation. The attack vector is local (AV:L), requires no privileges (PR:N), and has low attack complexity (AC:L), making it straightforward to exploit once the malicious file is delivered (Microsoft MSRC, Feedly).
Successful exploitation results in high confidentiality, integrity, and availability impacts on the local system, effectively constituting a complete compromise of the affected host. An attacker who tricks a user into opening a malicious Excel file can execute arbitrary code with elevated privileges, potentially enabling persistence, credential theft, or lateral movement within the network. The scope is limited to the local system (unchanged scope), but the privilege escalation component significantly amplifies the damage potential (Microsoft MSRC, Feedly).
.xlsx or .xls file designed to trigger a heap-based buffer overflow during parsing by Microsoft Excel, exploiting improper bounds checking in the file processing logic..xlsx/.xls files received via email or downloaded from external sources; new executables or scripts created in user-writable directories (e.g., %TEMP%, %APPDATA%) shortly after Excel is opened.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process running with unexpectedly elevated privileges.EXCEL.EXE (Event ID 1000/1001); security logs recording privilege escalation events (Event ID 4672) associated with the Excel process or its children.EXCEL.EXE or child processes to external IP addresses, particularly shortly after a file is opened.Microsoft released security updates on February 10, 2026 to address this vulnerability; affected users should apply the patch immediately via Windows Update or the Microsoft Update Catalog (Microsoft MSRC). Affected products include Microsoft 365 Apps for Enterprise, Excel 2016, Office 2019, Office 2021 LTSC, Office 2024 LTSC, and Office Online Server (patch to version 16.0.10417.20097 or later). As a workaround, organizations should restrict users from opening Excel files from untrusted or external sources, enforce Protected View settings in Office, and educate users about the risks of opening unsolicited file attachments (Feedly).
The vulnerability was covered as part of broader February 2026 Patch Tuesday reporting by multiple security outlets including BleepingComputer, Qualys, Rapid7, Sophos, and SANS ISC, which collectively noted the patch batch addressed 58 flaws including 6 zero-days (BleepingComputer, Qualys Blog, Rapid7). CVE-2026-21259 itself did not attract significant standalone commentary, as it was not among the actively exploited zero-days in the February release. Sophos and Flare.io also published Patch Tuesday reviews covering the broader update context (Sophos Blog, Flare Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."