
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21261 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to disclose sensitive information. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update. Affected products include Microsoft Excel 2016 (x86/x64), Office 2019 (x86/x64), Office 2021, Office 2024, Office Long Term Servicing Channel 2021/2024 (x86/x64/macOS), Office Online Server (before version 16.0.10417.20097), Microsoft 365 Apps for Enterprise (x86/x64), and Office for macOS 2021/2024. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), a memory safety flaw where Excel reads data beyond the bounds of an allocated buffer when processing a maliciously crafted spreadsheet file. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted Excel file, making the attack vector local with low complexity. The flaw is also mapped to CAPEC-540 (Overread Buffers), indicating that the out-of-bounds memory read can expose adjacent memory contents to the attacker. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Microsoft MSRC, Feedly).
Successful exploitation results in local information disclosure, with a high confidentiality impact and no impact to integrity or availability. An attacker who tricks a user into opening a malicious Excel spreadsheet could read sensitive data from process memory, potentially exposing credentials, cryptographic material, or other in-memory data. The attack is constrained to the local system and does not directly enable remote code execution or privilege escalation, limiting its scope but still posing a meaningful data exposure risk (Microsoft MSRC).
.xlsx/.xls/.xlsm files received via email or downloaded from untrusted sources; temporary files created in %TEMP% or %APPDATA% directories during Excel file parsing.EXCEL.EXE) crashes or application errors (Event ID 1000/1001) shortly after opening a spreadsheet; Dr. Watson or Windows Error Reporting logs referencing out-of-bounds memory access in Excel modules.EXCEL.EXE; unexpected network connections initiated by Excel to external IPs following file open events.Microsoft released security updates on February 10, 2026, addressing this vulnerability across all affected products. Administrators should apply the February 2026 Patch Tuesday updates immediately, prioritizing Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, and Office Online Server (update to version 16.0.10417.20097 or later). As an interim workaround, users should avoid opening Excel spreadsheets from untrusted or unknown sources, and organizations should consider enabling Protected View in Office to reduce exposure when opening files from external sources (Microsoft MSRC).
CVE-2026-21261 was covered as part of broader February 2026 Patch Tuesday roundups by multiple security outlets. Rapid7, Qualys, BleepingComputer, and Sophos all published Patch Tuesday summaries that included this vulnerability among the 58 flaws addressed in the February 2026 update cycle, though none highlighted it as a critical or high-priority item given its medium severity and lack of active exploitation. The SANS Internet Storm Center also noted the February 2026 update in its diary. Community sentiment reflects routine patching priority rather than urgent concern (BleepingComputer, Qualys Blog, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."