HighTLP:CLEARGARNET-CSIRT-2026-002

Microsoft Excel Remote Code Execution Vulnerability

Microsoft Excel Remote Code Execution Vulnerability

High severity. Remediate as a priority.

Summary

Microsoft Excel Remote Code Execution Vulnerability.

Impact

Exploitability signals: EPSS 1% · CVSS 8.8.

Affected systems

  • Microsoft Excel

Action

Review the vendor’s guidance and patch affected systems. Prioritise by exposure.

§ Verify this advisory✓ PGP-signed

This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:

$ curl -O https://csirt.garnet.edu.gh/advisories/2026-002-microsoft-excel-remote-code-execution-vulnerability.md
$ curl -O https://csirt.garnet.edu.gh/advisories/2026-002-microsoft-excel-remote-code-execution-vulnerability.md.asc
$ gpg --import garnet-csirt.asc
$ gpg --verify 2026-002-microsoft-excel-remote-code-execution-vulnerability.md.asc 2026-002-microsoft-excel-remote-code-execution-vulnerability.md

Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.


Think a system in the community is affected or compromised?Report an incident