CVE-2026-44818: Microsoft 365 Apps

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Affected products

  • Microsoft 365 Apps: affected versions not specified
  • Microsoft Excel: version 2016 only
  • Microsoft Microsoft 365: affected versions not specified
  • Microsoft Office 2019: affected versions not specified
  • Microsoft Office 2021: affected versions not specified
  • Microsoft Office 2024: affected versions not specified
  • Microsoft Office Online Server: affected versions not specified

Published 2026-06-09. Last modified 2026-07-23.