CVE-2026-32188 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. https://www.cve.org/CVERecord?id=CVE-2026-32188
Post summary
CVE-2026-32188 is an out‑of‑bounds read vulnerability in Microsoft Office Excel that permits local data disclosure by an unauthorized attacker.
CVE-2026-32188 | Microsoft 365 Apps for Enterprise | Information Disclosure
Description
Out-of-bounds read vulnerability in Microsoft Office Excel in Microsoft 365 Apps for Enterprise allows unauth local attackers to disclose sensitive information by opening a malicious Excel file that triggers the read beyond allocated memory bounds.
Severity: High
Exploitation: Unknown
Public PoC: Unknown
Patch Available: Yes
Affected Product: Microsoft 365 Apps for Enterprise
Affected Version: >= 16.0.1 and < https://aka.ms/OfficeSecurityReleases
Sources
Vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32188
Post summary
Microsoft Office Excel suffers an out-of-bounds read that could expose sensitive data; Microsoft has released a patch, but no exploitation evidence or PoC is disclosed.