CVE-2026-68807
Microsoft Excel Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-68807 is a Microsoft Excel bug that can let someone run harmful code on your computer if you open a specially crafted Excel file; if you receive unexpected spreadsheets, you should treat this as urgent and update.
CVE-2026-68807 is a Microsoft Excel memory-corruption weakness (CWE-122) that can lead to local remote code execution when a victim opens a malicious Excel file, without needing any login beforehand.
What to do now
- Check whether any affected Microsoft Office/Excel apps on your business devices are at or below the fixed versions (Windows Excel: 16.0.5565.1001; Mac Office/Excel: 16.112.26081010; Office Online Server: 16.0.10417.20175).
- Update Microsoft Excel/Microsoft Office (including Microsoft 365 Apps) to the fixed builds listed by Microsoft for CVE-2026-68807.
- For devices where patching is delayed, block or quarantine unexpected spreadsheet files from email and downloads (especially files from new or untrusted senders) until updates are applied.
- After updating, verify your version number changed to the fixed build on each endpoint and review email/security logs for suspicious Excel attachments.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-68807 and every CVE in our database. Create a free account — no credit card required.
Create Free Account