CVE-2026-32198: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5548.1000Patch KB5002860 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.108.26041219 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20113Patch KB5002855
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32198?
CVE-2026-32198 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-32198?
To fix CVE-2026-32198, apply the relevant patches provided by Microsoft for the affected versions of Excel and Office.
Which versions of Excel are affected by CVE-2026-32198?
CVE-2026-32198 affects multiple versions of Microsoft Excel, including Excel 2016 and various editions of Office LTSC 2021 and 2024.
What type of vulnerability is CVE-2026-32198?
CVE-2026-32198 is a use after free vulnerability that could allow an attacker to execute arbitrary code.
Is there a workaround for CVE-2026-32198?
Currently, the most effective way to mitigate CVE-2026-32198 is to ensure all affected software is updated with the latest security patches.