CVE-2026-55947: Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002886 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002884
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55947?
CVE-2026-55947 has a severity score of 7.8, categorizing it as high risk.
How do I fix CVE-2026-55947?
To remediate CVE-2026-55947, ensure that your Microsoft Excel and all Microsoft Office applications are updated to the latest security patches provided by Microsoft.
What systems are affected by CVE-2026-55947?
CVE-2026-55947 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office Online Server, Microsoft 365 Apps, Microsoft Excel, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
What type of vulnerability is CVE-2026-55947?
CVE-2026-55947 is classified as a heap-based buffer overflow vulnerability.
What impact does CVE-2026-55947 have?
CVE-2026-55947 allows an unauthorized attacker to execute code locally, potentially compromising the affected system.