CVE-2026-3463Disclosure(xlnt-community / xlnt)

LOWCVSS 7.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. Patch name: 147. It is suggested to install a patch to address this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xlnt

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Products
xlnt

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-03: 5Technical Details · 2026-03-03: 403-03
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3463 A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of … https://www.cve.org/CVERecord?id=CVE-2026-3463

    Post summary

    A weakness has been identified in xlnt-community xlnt up to version 1.6.1, affecting the binary_writer::append function in source/detail/binary.hpp.

    00010408
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3463 Heap-Based Buffer Overflow in xlnt-community xlnt 1.6.1 via Binary... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3463 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A heap-based buffer overflow vulnerability (CVE-2026-3463) was disclosed in xlnt-community xlnt 1.6.1, with details available on Vulmon, but no PoC, exploit, or patch information is provided.

    0001059
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3463 A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of … https://www.cve.org/CVERecord?id=CVE-2026-3463 ----- Traducción: CVE-2026-3463 Se … http://infoflow.cloud`

    Post summary

    A weakness in xlnt-community xlnt up to version 1.6.1 affecting the binary_writer::append function has been disclosed, with details available on CVE.org.

    0000025
    55 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3463 xlnt-community xlnt Compound Document binary.hpp append heap-based overflow Intel Report: https://ift.tt/WPFgBZf

    Post summary

    An alert announces CVE-2026-3463, a heap-based overflow in xlnt-community's Compound Document binary.hpp, and provides a link to an Intel report.

    0000033
    342 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3463 Intel Report: https://ift.tt/QrhCp1R

    Post summary

    A threat alert referencing CVE-2026-3463 with a link to an Intel Report, but no further details or actionable information are provided.

    0000033
    342 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxlnt-communityxlnt---

Explore more