cbcvebase.
CVE-2026-44818
published 2026-06-09

CVE-2026-44818: Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to…

PriorityP336high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
0.26%
18.0th percentile
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_excel_2016>= 16.0.0.0 < 16.0.5556.100116.0.5556.1001
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_365_for_mac>= 1.0.0 < 16.110.2606131716.110.26061317
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2024>= 16.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_for_mac_2021>= 16.0.1 < 16.110.2606131716.110.26061317
microsoftmicrosoft_office_ltsc_for_mac_2024>= 16.0.0 < 16.110.2606131716.110.26061317
microsoftoffice_online_server>= 16.0.0.0 < 16.0.10417.2013716.0.10417.20137
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.