CVE-2026-68811: Microsoft Excel Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Excel Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002903 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68811?
CVE-2026-68811 has a severity rating of 7.8, categorized as high.
How can I fix CVE-2026-68811?
To fix CVE-2026-68811, ensure that Microsoft Excel and other affected Microsoft Office products are updated to the latest version.
What types of affected software are involved in CVE-2026-68811?
CVE-2026-68811 affects Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, various Microsoft Office LTSC 2021 and 2024 editions, and Microsoft Office LTSC for Mac 2024.
What type of vulnerability is CVE-2026-68811?
CVE-2026-68811 is classified as a Remote Code Execution vulnerability caused by type confusion.
Who can be affected by CVE-2026-68811?
Any user of the affected Microsoft Excel versions can be targeted by an unauthorized attacker exploiting CVE-2026-68811.