Microsoft Office Excel: 25 Vulnerabilities Disclosed Together in August Patch Tuesday
Microsoft Office Excel faces a coordinated disclosure of 25 vulnerabilities, including high-severity flaws enabling local code execution and information disclosure.

Key findings
- Microsoft Office Excel: 25 vulnerabilities disclosed simultaneously on August 11, 2026.
- Batch includes multiple high-severity buffer overflow and out-of-bounds read/write flaws.
- Vulnerabilities could lead to local code execution and information disclosure.
- All 25 CVEs were addressed in Microsoft's August 2026 Patch Tuesday.
- No indication of in-the-wild exploitation for this specific batch of Excel vulnerabilities.
On August 11, 2026, Microsoft released a significant batch of 25 vulnerabilities affecting Microsoft Office Excel, disclosed simultaneously on Patch Tuesday. This coordinated disclosure event includes a mix of high and medium-severity flaws, with a strong emphasis on vulnerabilities that could lead to local code execution or information disclosure. The sheer volume and nature of these vulnerabilities underscore the importance of timely patching for users of Microsoft Office.
The disclosed vulnerabilities can be broadly categorized by their impact and the underlying bug class. A significant portion of the batch comprises buffer overflow vulnerabilities, including both heap-based and stack-based overflows. These flaws, such as CVE-2026-68815, CVE-2026-68812, CVE-2026-68813, CVE-2026-68807, CVE-2026-68801, CVE-2026-68800, CVE-2026-68798, CVE-2026-68796, CVE-2026-68795, CVE-2026-68816, CVE-2026-68817, and CVE-2026-68796, could allow an attacker to execute code locally.
Other critical vulnerabilities include out-of-bounds reads and writes, such as CVE-2026-68814, CVE-2026-68813, CVE-2026-68808, CVE-2026-68802, CVE-2026-70328, CVE-2026-70327, and CVE-2026-68797, which may lead to local information disclosure or code execution. Additionally, vulnerabilities like CVE-2026-68810 and CVE-2026-68803 involve type confusion, while CVE-2026-68804 presents a numeric truncation error, both potentially leading to local code execution. Improper input validation, as seen in CVE-2026-68818 and CVE-2026-68799, also contributes to the risk of local information disclosure or uninitialized resource use.
Microsoft's August 2026 Patch Tuesday addressed these 25 vulnerabilities affecting Microsoft Office Excel. While the provided information does not specify exact version numbers fixed, it is implied that applying the August 2026 security updates resolves these issues. Users are strongly advised to ensure their Microsoft Office suite is up to date to mitigate the risks associated with these vulnerabilities.
The simultaneous disclosure of these 25 CVEs highlights a focused patching effort by Microsoft. The prevalence of high-severity flaws, particularly those allowing for local code execution, makes it crucial for organizations and individuals to prioritize these updates. Staying informed about Microsoft's security advisories and applying patches promptly is essential for maintaining a secure computing environment.
The batch includes:
- Buffer Overflows: CVE-2026-68815, CVE-2026-68812, CVE-2026-68813, CVE-2026-68807, CVE-2026-68801, CVE-2026-68800, CVE-2026-68798, CVE-2026-68796, CVE-2026-68795, CVE-2026-68816, CVE-2026-68817, CVE-2026-68806, CVE-2026-68805, CVE-2026-68804, CVE-2026-68814, CVE-2026-68803, CVE-2026-68810, CVE-2026-68797, CVE-2026-68799, CVE-2026-68802, CVE-2026-68808, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328.
- Out-of-Bounds Reads/Writes: CVE-2026-68814, CVE-2026-68813, CVE-2026-68808, CVE-2026-68802, CVE-2026-70328, CVE-2026-70327, CVE-2026-68797.
- Type Confusion: CVE-2026-68810, CVE-2026-68803.
- Numeric Truncation: CVE-2026-68804.
- Improper Input Validation: CVE-2026-68818, CVE-2026-68799.
The related news coverage from Cisco Talos, Rapid7, Cyber Security News, and Vypr Intelligence confirms the simultaneous disclosure of these 25 vulnerabilities on August 11, 2026, as part of Microsoft's August Patch Tuesday. Notably, while one of the news articles mentions exploitation in the wild for a different Windows vulnerability (CVE-2026-68820), none of the provided information indicates that these specific Excel vulnerabilities were exploited in the wild. Rapid7 Blog Cyber Security News Vypr Intelligence