CVE-2026-21261
vulnerability analysis and mitigation

Overview

CVE-2026-21261 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to disclose sensitive information. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update. Affected products include Microsoft Excel 2016 (x86/x64), Office 2019 (x86/x64), Office 2021, Office 2024, Office Long Term Servicing Channel 2021/2024 (x86/x64/macOS), Office Online Server (before version 16.0.10417.20097), Microsoft 365 Apps for Enterprise (x86/x64), and Office for macOS 2021/2024. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), a memory safety flaw where Excel reads data beyond the bounds of an allocated buffer when processing a maliciously crafted spreadsheet file. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted Excel file, making the attack vector local with low complexity. The flaw is also mapped to CAPEC-540 (Overread Buffers), indicating that the out-of-bounds memory read can expose adjacent memory contents to the attacker. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in local information disclosure, with a high confidentiality impact and no impact to integrity or availability. An attacker who tricks a user into opening a malicious Excel spreadsheet could read sensitive data from process memory, potentially exposing credentials, cryptographic material, or other in-memory data. The attack is constrained to the local system and does not directly enable remote code execution or privilege escalation, limiting its scope but still posing a meaningful data exposure risk (Microsoft MSRC).

Exploitation steps

  1. Craft a malicious spreadsheet: An attacker creates a specially crafted Excel file (.xlsx, .xls, or similar) designed to trigger an out-of-bounds read in the Excel parsing engine when opened.
  2. Deliver the file to the target: The attacker distributes the malicious file via phishing email, malicious download link, or shared network drive, relying on social engineering to convince the victim to open it.
  3. Victim opens the file: When the target user opens the file in a vulnerable version of Microsoft Excel, the malformed data triggers the out-of-bounds read vulnerability.
  4. Memory disclosure: The out-of-bounds read causes Excel to access memory beyond the intended buffer, potentially exposing sensitive in-memory data (e.g., credentials, tokens, or other process memory contents) to the attacker.
  5. Exfiltrate disclosed data: Depending on the exploit implementation, the attacker may use additional techniques (e.g., embedded macros or secondary payloads) to capture and exfiltrate the disclosed memory contents (Microsoft MSRC).

Indicators of compromise

  • File System: Unexpected or suspicious .xlsx/.xls/.xlsm files received via email or downloaded from untrusted sources; temporary files created in %TEMP% or %APPDATA% directories during Excel file parsing.
  • Logs: Windows Event Logs showing Excel (EXCEL.EXE) crashes or application errors (Event ID 1000/1001) shortly after opening a spreadsheet; Dr. Watson or Windows Error Reporting logs referencing out-of-bounds memory access in Excel modules.
  • Process: Unusual child processes spawned by EXCEL.EXE; unexpected network connections initiated by Excel to external IPs following file open events.
  • Network: Outbound connections from the Excel process to unknown or suspicious external hosts, which may indicate a secondary payload attempting to exfiltrate disclosed data.

Mitigation and workarounds

Microsoft released security updates on February 10, 2026, addressing this vulnerability across all affected products. Administrators should apply the February 2026 Patch Tuesday updates immediately, prioritizing Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, and Office Online Server (update to version 16.0.10417.20097 or later). As an interim workaround, users should avoid opening Excel spreadsheets from untrusted or unknown sources, and organizations should consider enabling Protected View in Office to reduce exposure when opening files from external sources (Microsoft MSRC).

Community reactions

CVE-2026-21261 was covered as part of broader February 2026 Patch Tuesday roundups by multiple security outlets. Rapid7, Qualys, BleepingComputer, and Sophos all published Patch Tuesday summaries that included this vulnerability among the 58 flaws addressed in the February 2026 update cycle, though none highlighted it as a critical or high-priority item given its medium severity and lack of active exploitation. The SANS Internet Storm Center also noted the February 2026 update in its diary. Community sentiment reflects routine patching priority rather than urgent concern (BleepingComputer, Qualys Blog, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management