Vulnerability Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | 365 Apps | - |
| Microsoft | Excel | 2016 |
| Microsoft | Microsoft 365 | - |
| Microsoft | Office 2019 | - |
| Microsoft | Office 2021 | - |
| Microsoft | Office 2024 | - |
| Microsoft | Office Online Server | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-44818?
CVE-2026-44818 is a vulnerability with a CVSS score of 7.0 (HIGH). Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
How severe is CVE-2026-44818?
CVE-2026-44818 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44818?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft 365 Apps, Microsoft Excel, Microsoft Microsoft 365, Microsoft Office 2019, Microsoft Office 2021.