CVE-2026-44818

Summary

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Excel 201616.0.0.0 < 16.0.5556.1001affected
MicrosoftMicrosoft Office 201919.0.0 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office 365 for Mac1.0.0 < 16.110.26061317affected
MicrosoftMicrosoft Office LTSC 202116.0.1 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office LTSC 202416.0.0 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office LTSC for Mac 202116.0.1 < 16.110.26061317affected
MicrosoftMicrosoft Office LTSC for Mac 202416.0.0 < 16.110.26061317affected
MicrosoftOffice Online Server16.0.0.0 < 16.0.10417.20137affected

Weaknesses

  • CWE-362: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References