CVE-2026-79592

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

Published 2026-09-10. Last modified 2026-09-22.