What is CVE-2026-59933?
A vulnerability has been discovered in the OLE reader component of the PhpSpreadsheet library. Through specially crafted XLS files, an attacker can manipulate sector chains. Systems using the affected versions should be updated immediately.
Azərbaycanca: PhpSpreadsheet kitabxanasının OLE reader komponentində zəiflik aşkar edilib. Xüsusi hazırlanmış XLS faylları vasitəsilə təcavüzkar sector chain-ləri manipulyasiya edə bilər. Təsirə məruz qalan versiyalardan istifadə edən sistemlər dərhal yenilənməlidir.
FAQ2
Through which file type can an attacker exploit CVE-2026-59933?
CVE-2026-59933 can be exploited through specially crafted XLS files.
In which component of the PhpSpreadsheet library was CVE-2026-59933 discovered?
CVE-2026-59933 was discovered in the OLE reader component of the PhpSpreadsheet library.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.