cbcvebase.
CVE-2026-32199
published 2026-04-14

CVE-2026-32199: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected

13 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_excel_2016>= 16.0.0.0 < 16.0.5548.100016.0.5548.1000
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2024>= 16.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_for_mac_2021>= 16.0.1 < 16.108.2604121916.108.26041219
microsoftmicrosoft_office_ltsc_for_mac_2024>= 16.0.0 < 16.108.2604121916.108.26041219
microsoftoffice
microsoftoffice_long_term_servicing_channel
microsoftoffice_long_term_servicing_channel
microsoftoffice_online_server< 16.0.10417.2011316.0.10417.20113
microsoftoffice_online_server>= 16.0.0.0 < 16.0.10417.2011316.0.10417.20113