CVE-2026-55136: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Other sources
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002884 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002886 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55136?
The severity of CVE-2026-55136 is classified as high with a score of 7.8.
How do I fix CVE-2026-55136?
To fix CVE-2026-55136, update Microsoft Excel and other affected Microsoft Office applications to the latest versions.
What applications are affected by CVE-2026-55136?
CVE-2026-55136 affects Microsoft Excel 2016, Microsoft Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
What type of vulnerability is CVE-2026-55136?
CVE-2026-55136 is a remote code execution vulnerability caused by an untrusted pointer dereference in Microsoft Excel.
What can happen if CVE-2026-55136 is exploited?
If exploited, CVE-2026-55136 allows an unauthorized attacker to execute code locally on the affected system.