CVE-2026-44817: Microsoft Excel Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1001Patch KB5002877 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20137Patch KB5002875
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44817?
CVE-2026-44817 has a high severity rating of 7.8.
What vulnerability type is CVE-2026-44817?
CVE-2026-44817 is classified as a remote code execution vulnerability in Microsoft Excel.
How do I fix CVE-2026-44817?
To fix CVE-2026-44817, install the latest security updates for Microsoft Excel provided by Microsoft.
What software is affected by CVE-2026-44817?
CVE-2026-44817 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office Online Server, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
What is the potential impact of CVE-2026-44817?
The potential impact of CVE-2026-44817 allows unauthorized code execution locally on affected systems.