CVE-2026-44823: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Other sources
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1001Patch KB5002877 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20137Patch KB5002875
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44823?
CVE-2026-44823 has a high severity rating of 7.8.
How do I fix CVE-2026-44823?
To fix CVE-2026-44823, update Microsoft Excel to the latest version provided by Microsoft.
What is the impact of CVE-2026-44823?
CVE-2026-44823 allows an unauthorized attacker to execute code locally on affected systems.
Which software is affected by CVE-2026-44823?
CVE-2026-44823 affects various versions of Microsoft Excel, including Microsoft 365 Apps for Enterprise and multiple editions of Microsoft Office LTSC.
What type of vulnerability is CVE-2026-44823?
CVE-2026-44823 is classified as an integer underflow vulnerability leading to remote code execution.