What is CVE-2026-59932?
A vulnerability in the Gnumeric reader of the PhpSpreadsheet library allows attackers to manipulate memory via crafted .gnumeric files. This affects a wide range of versions up to 1.30.5 and various other release lines. Users are advised to upgrade to the latest patched version.
Azərbaycanca: PhpSpreadsheet kitabxanasında Gnumeric fayl oxuyucusu zəifliyi aşkarlanıb, təcavüzkar xüsusi hazırlanmış .gnumeric faylları vasitəsilə yaddaşa müdaxilə edə bilər. Bu zəiflik 1.30.5-ə qədər bütün versiyalar da daxil olmaqla geniş versiya aralığına təsir göstərir. İstifadəçilərə kitabxananı ən son təhlükəsizlik yaması ilə yeniləmək tövsiyə olunur.
FAQ2
Through which file type can CVE-2026-59932 be exploited in the PhpSpreadsheet library?
The vulnerability can be exploited via specially crafted .gnumeric files.
What measure should be taken to mitigate CVE-2026-59932?
Users are advised to upgrade the library to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.