Known Vulnerabilities for Excel Web App by Microsoft
Listed below are 6 of the newest known vulnerabilities associated with "Excel Web App" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86745 json | Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in ... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86742 json | Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsC... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-86257 json | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym mem... | Not Provided | 2026-09-06 | 2026-09-08 |
| CVE-2026-85875 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-85661 json | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to ... | Not Provided | 2026-09-04 | 2026-09-04 |
| CVE-2026-84374 json | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the ... | Not Provided | 2026-09-01 | 2026-09-04 |
| CVE-2026-81960 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-81959 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-81958 json | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-81957 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-09-08 | 2026-09-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Excel Web App | 2010 |