CVE-2026-32199

CWE-416Use After Free3 documents3 sources
Severity
7.8HIGH
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14

Description

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5microsoft/microsoft_excel_201616.0.0.016.0.5548.1000
CVEListV5microsoft/office_online_server16.0.0.016.0.10417.20113
CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_202116.0.1https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_202416.0.0https://aka.ms/OfficeSecurityReleases

🔴Vulnerability Details

2
CVEList
Microsoft Excel Remote Code Execution Vulnerability2026-04-14
VulDB
Microsoft Office 2019/LTSC/LTSC 2021/LTSC 2024 Excel use after free2026-04-14
CVE-2026-32199 (HIGH CVSS 7.8) | Use after free in Microsoft Office | cvebase.io