CVE-2026-40359Patch(microsoft / 365_apps)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_apps systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • excel
  • office
  • office_long_term_servicing_channel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
365_appsexcelofficeoffice_long_term_servicing_channeloffice_online_server

5 versions affected across 5 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-15: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-24: 105-1205-1506-24
Signal classification3 categories
Patch
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-151
General1
2026-06-241
Disclosure1
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    🚨تحديثات مايكروسوفت لشهر مايو 2026 قفلت مجموعه من الثغرات الخطيرة على المستخدمين العاديين و المنظمات ملخص الثغرات المهمه من وجهه نظري 📍CVE-2026-41089 في Windows Netlogon التقييم: 9.8 ثغرة RCE قبل المصادقة في Netlogon. خطورتها عالية جداً لأنها تسهل استهداف Domain Controllers، وقد تسمح بتنفيذ كود بصلاحيات عالية بدون حساب مسبق إذا توفرت شروط الاستغلال. هذي اهم ثغره ولازم تعطيها اولولية حالياً 📍CVE-2026-41096 في Windows DNS Client التقييم: 9.8 ثغرة Heap-based buffer overflow في dnsapi.dll. المهاجم قد يستغلها عبر استجابة لطلب DNS خبيث لتنفيذ كود عبر الشبكة. السيناريو الأخطر يظهر إذا قدر يتحكم في مسار DNS أو يستخدم DNS server خبيث أو هجمات Man-in-the-Middle 📍CVE-2026-42898 في Dynamics 365 On-Premises التقييم: 9.9 ثغرة RCE في Dynamics 365 On-Premises خلل في التحكم بعملية توليد الكود داخل Microsoft Dynamics 365 On-Premises يسمح لمهاجم مصادق بتنفيذ كود عبر الشبكة. 📍CVE-2026-40364 في Microsoft Word التقييم: 8.4 ثغرة RCE في Word. الخطر أنها قد تُستغل عند فتح أو معاينة ملف خبيث عبر Preview Pane في بعض السيناريوهات. انتبه ياصديقي لا تركز على نظام التشغيل فقط وتنسى Office. مرفق واحد قد يكون بداية الاختراق 📍CVE-2026-35439 وCVE-2026-40365 في SharePoint Server التقييم: 8.8 ثغرات RCE في SharePoint Server. SharePoint غالباً يحتوي ملفات داخلية، صلاحيات كبيرة ، وربط مع Active Directory. استغلاله قد يعطي المهاجم فرصة للوصول للشبكة الداخلية ويفتح باب للتنقل في الشبكه ايضا. 📍CVE-2026-40370 في SQL Server التقييم: 8.8 ثغرة RCE في SQL Server، لكنها تتطلب صلاحيات منخفضة. الخطر يرتفع إذا كان الخادم مكشوفاً على الانترنت أو إذا حصل المهاجم على حساب محدود. 📍CVE-2026-40415 في Windows TCP/IP التقييم: 8.1 ثغرة RCE في Network Stack نفسه. الخطورة أنها لا تعتمد على ملف Word أو Excel أو رابط تصيد. الاستغلال يتم من خلال الشبكة من خلال حزم مصممة بطريقة معينة. 📍CVE-2026-34332 في Windows Kernel-Mode Driver التقييم: 8.0 ثغرة RCE في Kernel-Mode Driver. عالية الخطورة لأنها مرتبطة طبقة حساسة من النظام. 📍CVE-2026-40359 في Excel التقييم: 7.8 ثغرة RCE في Excel. فتح أو معاينة ملف Excel خبيث قد يؤدي إلى تنفيذ كود على جهاز الضحية. هذا النوع من الثغرات مهم لأن ملفات Office ما زالت من أكثر أدوات الهجوم استخداماً داخل المؤسسات. 📍CVE-2026-34342 في Windows Print Spooler التقييم: 7.0 ثغرة Elevation of Privilege. ليست PrintNightmare جديدة، لكنها تذكرنا أن Print Spooler ما زال سطح هجوم مهم بعد الاختراق الأولي. إذا الخدمة غير مطلوبة على بعض الخوادم، عطّلها. وإذا مطلوبة، حدثها وراقب استخدامها

    Post summary

    The text announces multiple high‑severity CVEs with technical details but does not provide evidence of exploitation, PoCs, or specific patches, classifying it as a general advisory.

    03125912.7K
    50.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Excel also receives critical attention: CVE-2026-40359 (Excel RCE, Important) — Memory corruption via spreadsheet cells CVE-2026-40362 (Excel RCE, Important) — Malicious formula injection chains

    Post summary

    The message announces two new Excel RCE vulnerabilities, providing brief technical details, but contains no evidence of Proof of Concept, exploitation, patches, or misconceptions.

    1000031
    295 followersView on X
  • WindowsForum@windowsforum
    Patch

    🧨 CVE-2026-40359 is Excel RCE again—because spreadsheets needed a boss fight. Patch now: your inbox shouldn’t double as a remote-access delivery system. #Windows #Security https://windowsforum.com/threads/cve-2026-40359-excel-remote-code-execution-why-you-must-patch-now.417954/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #ExcelSecurity #OfficeRce #WindowsEnterprise #Microsoft365Patching https://t.co/emrAl2T9Iq

    Post summary

    The tweet announces the CVE‑2026‑40359 Excel RCE vulnerability and urges immediate patching, with links to further details.

    0000053
    1.1K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftexcel2016-x64
Appmicrosoftexcel2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-
Appmicrosoftoffice_online_server---

Explore more