CVE-2026-40359: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5552.1000Patch KB5002865 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.109.26051019 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20128Patch KB5002871
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40359?
CVE-2026-40359 is classified as a critical vulnerability that allows remote code execution in Microsoft Excel.
How do I fix CVE-2026-40359?
To fix CVE-2026-40359, users should apply the latest security updates provided by Microsoft for their affected version of Excel.
Which versions of Microsoft Excel are affected by CVE-2026-40359?
CVE-2026-40359 affects multiple versions of Microsoft Excel, including Excel 2016, Office LTSC 2021 and 2024, and Office 2019.
What type of attack does CVE-2026-40359 allow?
CVE-2026-40359 allows unauthorized attackers to execute arbitrary code on the affected system through a maliciously crafted Excel file.
Is there a workaround for CVE-2026-40359?
Currently, the best mitigation for CVE-2026-40359 is to update to the latest security patch provided by Microsoft as no temporary workaround is documented.