CVE-2026-3779
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
HIGH · CVSS 7.8
EPSS 0.00023
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules15
YARA rules0