
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32199 is a use-after-free vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday, it affects a wide range of Microsoft Office products including Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, Office Online Server, and macOS variants of Office 2021 and 2024. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), meaning Excel improperly reuses or references memory after it has been freed, potentially allowing an attacker to control execution flow by manipulating the reallocated memory region. Exploitation requires a local attack vector with low complexity and no privileges, but does require user interaction — specifically, a victim must open a specially crafted Excel file. No public technical write-ups or proof-of-concept code detailing the precise trigger mechanism have been identified at this time (MSRC Advisory, GitHub Advisory).
Successful exploitation results in arbitrary code execution on the victim's system with the privileges of the logged-in user, yielding high confidentiality, integrity, and availability impact. An attacker who tricks a user into opening a malicious Excel file could install malware, exfiltrate sensitive data, or pivot to other systems on the network. Affected products span Windows and macOS platforms across multiple Office release channels, broadening the potential attack surface (MSRC Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (MSRC Advisory). The EPSS score is approximately 0.058–0.068%, placing it in roughly the 21st percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
.xlsx or .xls file designed to trigger the use-after-free condition in Excel's memory management routines upon parsing.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after a user opens an Excel file.%TEMP%, %APPDATA%, or startup folders by the Excel process; newly created scripts or executables in user-writable directories.EXCEL.EXE to external IP addresses or domains, particularly immediately after file open events.EXCEL.EXE as a parent process for unusual child processes; application crash logs or Watson error reports referencing Excel memory access violations.Microsoft released patches on April 14, 2026, addressing this vulnerability across all affected products. Specific patched versions include Office Online Server 16.0.10417.20113 or later, and Excel 2016 version 16.0.5548.1000 or later; for Office LTSC 2021/2024 and Microsoft 365 Apps, refer to Microsoft's official release guidance at https://aka.ms/OfficeSecurityReleases. As a workaround prior to patching, organizations should block Excel files from untrusted or external sources, enable Protected View for files received from the internet, and consider application whitelisting to restrict Excel's ability to spawn child processes (MSRC Advisory).
The vulnerability was covered as part of broader reporting on Microsoft's April 2026 Patch Tuesday, which addressed 167 flaws in total (BleepingComputer, Computerworld). Zero Day Initiative published a security update review for April 2026 that included analysis of the month's Office vulnerabilities (ZDI Blog). Researcher Haifei Li commented on the vulnerability via social media, and Cybersecurity News also covered the Patch Tuesday release (CybersecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."