CVE-2026-32199: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5548.1000Patch KB5002860 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.108.26041219 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20113Patch KB5002855
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32199?
CVE-2026-32199 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2026-32199?
You can resolve CVE-2026-32199 by applying the latest security patches provided by Microsoft for the affected Office applications.
Which products are affected by CVE-2026-32199?
CVE-2026-32199 affects multiple versions of Microsoft Excel and Office products, including Office LTSC for Mac and Office 2019.
Can CVE-2026-32199 be exploited remotely?
Yes, CVE-2026-32199 allows an unauthorized attacker to execute code locally, making it a serious security concern.
Is there a workaround for CVE-2026-32199 until I can apply the patch?
Currently, the best practice is to update to the latest version of affected software, as there are no recommended workarounds available.