CVE-2026-68803: Microsoft Excel Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002903
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68803?
CVE-2026-68803 has a high severity rating of 7.8.
What does CVE-2026-68803 affect?
CVE-2026-68803 affects Microsoft Excel and various editions of Microsoft Office.
How can I mitigate CVE-2026-68803?
To mitigate CVE-2026-68803, ensure that you install all available security updates provided by Microsoft.
What type of vulnerability is CVE-2026-68803?
CVE-2026-68803 is a remote code execution vulnerability caused by type confusion.
Who is impacted by CVE-2026-68803?
Users of Microsoft Excel and Microsoft 365 applications are impacted by CVE-2026-68803.