CVE-2026-32199
vulnerability analysis and mitigation

Overview

CVE-2026-32199 is a use-after-free vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday, it affects a wide range of Microsoft Office products including Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, Office Online Server, and macOS variants of Office 2021 and 2024. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), meaning Excel improperly reuses or references memory after it has been freed, potentially allowing an attacker to control execution flow by manipulating the reallocated memory region. Exploitation requires a local attack vector with low complexity and no privileges, but does require user interaction — specifically, a victim must open a specially crafted Excel file. No public technical write-ups or proof-of-concept code detailing the precise trigger mechanism have been identified at this time (MSRC Advisory, GitHub Advisory).

Impact

Successful exploitation results in arbitrary code execution on the victim's system with the privileges of the logged-in user, yielding high confidentiality, integrity, and availability impact. An attacker who tricks a user into opening a malicious Excel file could install malware, exfiltrate sensitive data, or pivot to other systems on the network. Affected products span Windows and macOS platforms across multiple Office release channels, broadening the potential attack surface (MSRC Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (MSRC Advisory). The EPSS score is approximately 0.058–0.068%, placing it in roughly the 21st percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Craft a malicious Excel file: An attacker creates a specially crafted .xlsx or .xls file designed to trigger the use-after-free condition in Excel's memory management routines upon parsing.
  2. Deliver the file to the target: The attacker distributes the malicious file via phishing email, malicious download link, or other social engineering methods to lure the victim into opening it.
  3. Victim opens the file: When the target opens the file in a vulnerable version of Microsoft Excel, the use-after-free condition is triggered, causing Excel to reference freed memory.
  4. Achieve code execution: By controlling the contents of the reallocated memory region, the attacker redirects execution flow to attacker-controlled shellcode or a payload, executing arbitrary code with the privileges of the current user.
  5. Post-exploitation: With code execution established, the attacker may deploy additional malware, establish persistence, exfiltrate data, or move laterally within the network (MSRC Advisory, GitHub Advisory).

Indicators of compromise

  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after a user opens an Excel file.
  • File System: Unexpected files written to %TEMP%, %APPDATA%, or startup folders by the Excel process; newly created scripts or executables in user-writable directories.
  • Network: Outbound connections from EXCEL.EXE to external IP addresses or domains, particularly immediately after file open events.
  • Logs: Windows Event Log entries (Event ID 4688) showing EXCEL.EXE as a parent process for unusual child processes; application crash logs or Watson error reports referencing Excel memory access violations.
  • Memory: Heap corruption or access violation exceptions in Excel process memory, potentially captured by endpoint detection tools.

Mitigation and workarounds

Microsoft released patches on April 14, 2026, addressing this vulnerability across all affected products. Specific patched versions include Office Online Server 16.0.10417.20113 or later, and Excel 2016 version 16.0.5548.1000 or later; for Office LTSC 2021/2024 and Microsoft 365 Apps, refer to Microsoft's official release guidance at https://aka.ms/OfficeSecurityReleases. As a workaround prior to patching, organizations should block Excel files from untrusted or external sources, enable Protected View for files received from the internet, and consider application whitelisting to restrict Excel's ability to spawn child processes (MSRC Advisory).

Community reactions

The vulnerability was covered as part of broader reporting on Microsoft's April 2026 Patch Tuesday, which addressed 167 flaws in total (BleepingComputer, Computerworld). Zero Day Initiative published a security update review for April 2026 that included analysis of the month's Office vulnerabilities (ZDI Blog). Researcher Haifei Li commented on the vulnerability via social media, and Cybersecurity News also covered the Patch Tuesday release (CybersecurityNews).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management