CVE-2026-55031: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002886 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002884
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55031?
CVE-2026-55031 has a severity rating of 7.8, categorized as high.
What types of software are affected by CVE-2026-55031?
CVE-2026-55031 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office Online Server, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
What is the impact of CVE-2026-55031?
CVE-2026-55031 allows an unauthorized attacker to execute code locally due to an out-of-bounds read in Microsoft Excel.
How do I fix CVE-2026-55031?
To fix CVE-2026-55031, users should apply the latest security updates provided by Microsoft for the affected software.
What is the exploit vector of CVE-2026-55031?
CVE-2026-55031 can be exploited through local access, making user interaction a requirement.