CVE-2026-56156: Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215
Event History
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
The attacker must cause Excel to process malicious content and requires user interaction. The CVSS vector indicates exploitation is local, has low attack complexity, and requires no attacker privileges.
What could successful exploitation allow?
Successful exploitation could allow code execution with high impact to confidentiality, integrity, and availability.
Which Excel deployments are identified as affected?
The affected software list includes Microsoft 365 Apps, Office 2021, Office 2024, Office LTSC 2021 and 2024 32-bit and 64-bit editions, and Office LTSC for Mac 2021.