CVE-2026-55024: Microsoft Excel Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002886 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002884
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55024?
CVE-2026-55024 has a severity rating of 7.8, categorized as high.
How does CVE-2026-55024 affect Microsoft Excel users?
CVE-2026-55024 allows unauthorized attackers to execute code locally through type confusion vulnerabilities in Microsoft Excel.
What versions of Microsoft software are impacted by CVE-2026-55024?
CVE-2026-55024 affects Microsoft Excel, Microsoft Office 2016, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
How do I fix CVE-2026-55024?
To address CVE-2026-55024, users are advised to install the latest security updates provided by Microsoft.
Is CVE-2026-55024 a remote code execution vulnerability?
Yes, CVE-2026-55024 is classified as a remote code execution vulnerability in Microsoft Excel.