CVE-2026-62870: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002886
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62870?
CVE-2026-62870 has a severity rating of high at 8.8.
How does CVE-2026-62870 affect Microsoft Excel?
CVE-2026-62870 allows an unauthorized attacker to execute remote code through a use after free vulnerability in Microsoft Excel.
What versions of Microsoft Excel are impacted by CVE-2026-62870?
CVE-2026-62870 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, and Microsoft Office 2019 for both 32-bit and 64-bit editions.
How can I fix CVE-2026-62870?
Fixing CVE-2026-62870 involves applying the latest security updates provided by Microsoft for affected versions of Excel.
What is the exploitability level of CVE-2026-62870?
CVE-2026-62870 is exploitable over a network with low access complexity and requires user interaction.