CVE-2026-40359
published 2026-05-12CVE-2026-40359: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
PriorityP347high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.33%
25.6th percentile
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_excel_2016 | >= 16.0.0.0 < 16.0.5552.1000 | 16.0.5552.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.109.26051019 | 16.109.26051019 |
| microsoft | microsoft_office_ltsc_for_mac_2024 | >= 16.0.0 < 16.109.26051019 | 16.109.26051019 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_online_server | < 16.0.10417.20128 | 16.0.10417.20128 |
| microsoft | office_online_server | >= 16.0.0.0 < 16.0.10417.20128 | 16.0.10417.20128 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Excel up to Office Online Server use after free
vuldb·2026-05-12
CVE-2026-40359 [CRITICAL] Microsoft Excel up to Office Online Server use after free
A vulnerability described as critical has been identified in Microsoft Excel up to Office Online Server. The impacted element is an unknown function. Executing a manipulation can lead to use after free.
This vulnerability is tracked as CVE-2026-40359. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-whc2-9r39-wqcm: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally
ghsa_unreviewed·2026-05-12
CVE-2026-40359 [HIGH] CWE-416 GHSA-whc2-9r39-wqcm: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
No detection rules found.
No public exploits indexed.
2026-05-12
Published