Use After Free Vulnerability in Microsoft Office Excel
CVE-2026-40359
7.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40359?
A use after free vulnerability in Microsoft Office Excel could allow an unauthorized attacker to execute arbitrary code on the user's machine. This exploitation occurs when a program attempts to access memory after it has been freed, potentially leading to a system compromise. It is crucial for users to apply the latest updates and security patches to mitigate this risk.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Excel 2016 32-bit Systems 16.0.0.0 < 16.0.5552.1000
Microsoft Office 2019 32-bit Systems 19.0.0