CVE-2026-40362Patch(microsoft / 365_apps)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_apps systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • excel
  • office
  • office_long_term_servicing_channel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
365_appsexcelofficeoffice_long_term_servicing_channeloffice_online_server

5 versions affected across 5 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-12: 1Mentions · 2026-06-24: 1Mentions · 2026-07-09: 1Mentions · 2026-09-18: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-09-18: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-09: 1Technical Details · 2026-09-18: 105-1206-2407-0909-18
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-06-241
Disclosure1
2026-07-091
Disclosure1
2026-09-181
Patch1
Full discourse4 posts
  • 0patch@0patch
    Patch

    Micropatches released for Microsoft Excel Remote Code Execution Vulnerability (CVE-2026-40362) https://0patch.com/blog/micropatches-released-for-microsoft-excel-remote-code-execution-vulnerability-cve-2026-40362 https://t.co/dBgvPU0TDw

    Post summary

    The tweet announces that micropatches have been released for CVE-2026-40362, a remote code execution vulnerability in Microsoft Excel, and links to the 0patch blog for details.

    14052816
    8.4K followersView on X
  • S2W@S2W_Official
    Disclosure

    NEW S2W Report: Microsoft Office Excel #Vulnerability - CVE-2026-40362 S2W Threat Intelligence Center TALON analyzed CVE-2026-40362, a #Microsoft Office Excel Remote Code Execution vulnerability first discovered by Jeongmin Choi with S2W and Haein Lee with KAIST Hacking Lab. This vulnerability is a Heap-based Buffer Overflow vulnerability caused by improper boundary checking in the PivotTable record loader of Microsoft Office #Excel. The flaw stems from the handler IRLOADSXVIEW::HrLoadSXDI14 failing to validate the SXDI data item count. When the count is zero, a threat actor can write controlled values before the start of the array buffer, corrupting heap memory as soon as a manipulated workbook is opened. Explore the report by S2W Threat Intelligence Center TALON at the link below. https://s2w.inc/en/resource/detail/1095?utm_source=twitter&utm_medium=social-posts&utm_campaign=ti-reports&utm_term=vulnerability&utm_content=cve-2026-40362

    Post summary

    The report discloses a heap‑based buffer overflow in Microsoft Office Excel’s PivotTable loader, outlining how improper boundary checks enable heap corruption, but it does not provide a PoC, exploit, or patch.

    00011363
    1.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Excel also receives critical attention: CVE-2026-40359 (Excel RCE, Important) — Memory corruption via spreadsheet cells CVE-2026-40362 (Excel RCE, Important) — Malicious formula injection chains

    Post summary

    The text announces two Excel RCE vulnerabilities with specific technical details, but provides no evidence of PoCs, exploits, patches, or active exploitation.

    1000031
    295 followersView on X
  • WindowsForum@windowsforum
    Patch

    🧨 CVE-2026-40362 Excel RCE: because apparently spreadsheets aren’t scary enough—now they can run code. Patch fast, and treat “friendly” .xlsx like a suspicious download. #Windows #Security https://windowsforum.com/threads/cve-2026-40362-excel-rce-patch-harden-and-tame-malicious-workbook-handling.417957/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PatchManagement #ExcelSecurity #OfficeRce #DocumentSupplyChain https://t.co/2nptVsea3f

    Post summary

    The post announces the CVE-2026-40362 Excel RCE vulnerability and urges readers to apply a patch and treat .xlsx files with caution, without providing technical details or evidence of active exploitation.

    0000041
    1.1K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftexcel2016-x64
Appmicrosoftexcel2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-
Appmicrosoftoffice_online_server---

Explore more