CVE-2026-68807: Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002903 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68807?
The severity of CVE-2026-68807 is high with a CVSS score of 7.8.
How does CVE-2026-68807 affect Microsoft Excel?
CVE-2026-68807 allows an unauthorized attacker to execute remote code on affected Microsoft Excel applications due to a heap-based buffer overflow.
Which versions of Microsoft Excel are affected by CVE-2026-68807?
CVE-2026-68807 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office Excel, and various versions of Microsoft Office LTSC.
How can I mitigate the risks associated with CVE-2026-68807?
To mitigate CVE-2026-68807, ensure that your Microsoft Excel applications are updated with the latest security patches provided by Microsoft.
What type of attack does CVE-2026-68807 facilitate?
CVE-2026-68807 facilitates remote code execution attacks, allowing unauthorized code execution on the target machine.