CVE-2026-26108: Microsoft Excel Remote Code Execution Vulnerability
Published Mar 10, 2026
·Updated
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
27 affected componentsFixes available
Microsoft Excel 2016
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft Excel 2016
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft Office LTSC for Mac 2021
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft Office 2019 for 64-bit editions
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft Office LTSC for Mac 2024
Microsoft Office Online Server
Microsoft 365 Apps for Enterprise
Microsoft Office 2019 for 32-bit editions
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft Excel=2016
Microsoft Excel=2016
Microsoft Office=2019
Microsoft Office=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel Macos=2021
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel Macos=2024
Microsoft Office Online Server<16.0.10417.20102
Microsoft Office Online Server
Event History
Mar 10, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26108?
CVE-2026-26108 is classified as a high-severity remote code execution vulnerability.
2
How do I fix CVE-2026-26108?
To fix CVE-2026-26108, install the latest security updates provided by Microsoft for affected Excel products.
3
Which versions of Excel are affected by CVE-2026-26108?
CVE-2026-26108 affects multiple versions including Excel 2016, Office LTSC 2024, and Office 2019.
4
What type of vulnerability is CVE-2026-26108?
CVE-2026-26108 is a heap-based buffer overflow vulnerability allowing remote code execution.
5
Can CVE-2026-26108 be exploited remotely?
Yes, CVE-2026-26108 can be exploited by an unauthorized attacker to execute code locally.