Severity
5.5MEDIUM
EPSS
0.1%
top 82.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages12 packages

CVEListV5microsoft/microsoft_excel_201616.0.0.016.0.5539.1002
CVEListV5microsoft/office_online_server16.0.0.016.0.10417.20097
NVDmicrosoft/office_online_server< 16.0.10417.20097
CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_202116.0.1https://aka.ms/OfficeSecurityReleases

🔴Vulnerability Details

2
GHSA
GHSA-v8pc-rxff-x74j: Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally2026-02-10
CVEList
Microsoft Excel Information Disclosure Vulnerability2026-02-10

📋Vendor Advisories

1
Microsoft
Microsoft Excel Information Disclosure Vulnerability2026-02-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-21258 Impact, Exploitability, and Mitigation Steps | Wiz