CVE-2026-65807
8.8Microsoft · Excel / 365 Apps
A type confusion vulnerability in Microsoft Excel allows an unauthorized attacker to achieve remote code execution via a specially crafted file.
Executive summary
A critical type confusion vulnerability in Microsoft Excel permits an unauthorized attacker to execute arbitrary code when a user opens a malicious file.
Vulnerability
The flaw is caused by type confusion (CWE-843) when processing resources. An attacker can exploit this by enticing a user to open a malicious document, resulting in remote code execution with the permissions of the current user.
Business impact
This vulnerability carries a CVSS score of 8.8, indicating a high risk of remote code execution. If exploited, an attacker could gain complete control over the victim's workstation, leading to significant data breaches, the installation of malware, or lateral movement within the corporate network.
Remediation
Immediate Action: Update Microsoft Office and Excel installations to the latest available versions via the official Microsoft security release portal.
Proactive Monitoring: Monitor endpoint detection and response systems for suspicious process spawning from the Excel application.
Compensating Controls: Utilize email filtering solutions to block potentially malicious attachments and encourage users to utilize Protected View for documents from untrusted sources.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the potential for remote code execution, organizations should treat this update with high priority. Ensure that all Office software is updated and warn users against opening unexpected or untrusted Excel documents.