CVE-2026-65807

8.8

Microsoft · Excel / 365 Apps

A type confusion vulnerability in Microsoft Excel allows an unauthorized attacker to achieve remote code execution via a specially crafted file.

Executive summary

A critical type confusion vulnerability in Microsoft Excel permits an unauthorized attacker to execute arbitrary code when a user opens a malicious file.

Vulnerability

The flaw is caused by type confusion (CWE-843) when processing resources. An attacker can exploit this by enticing a user to open a malicious document, resulting in remote code execution with the permissions of the current user.

Business impact

This vulnerability carries a CVSS score of 8.8, indicating a high risk of remote code execution. If exploited, an attacker could gain complete control over the victim's workstation, leading to significant data breaches, the installation of malware, or lateral movement within the corporate network.

Remediation

Immediate Action: Update Microsoft Office and Excel installations to the latest available versions via the official Microsoft security release portal.

Proactive Monitoring: Monitor endpoint detection and response systems for suspicious process spawning from the Excel application.

Compensating Controls: Utilize email filtering solutions to block potentially malicious attachments and encourage users to utilize Protected View for documents from untrusted sources.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the potential for remote code execution, organizations should treat this update with high priority. Ensure that all Office software is updated and warn users against opening unexpected or untrusted Excel documents.

More Microsoft CVEs