CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] Microsoft Excel (2016), Office (2019, 2021 and 2024) and 365 Apps: Vulnerability allows code execution

highCVE-2026-62870
A remote anonymous attacker can exploit a vulnerability in Microsoft Excel 2016, Microsoft Office 2024, Microsoft Office 2021, Microsoft 365 Apps Enterprise and Microsoft Office 2019 to execute arbitrary code.

CSIRTS triage

vendor: Microsoftproduct: Excel and OfficeRemote code executionaffected: Excel 2016, Office 2019, Office 2021, Office 2024, 365 Apps
What
A remote attacker can execute arbitrary code in Microsoft Excel and Office products through an unauthenticated attack.
Who is affected
Organizations and users running Microsoft Excel 2016, Office 2019, 2021, 2024, and 365 Apps.
Urgency
Critical priority; unauthenticated remote code execution in widely-used productivity software requires emergency patching.
Action
Apply Microsoft security updates for Excel and Office products addressing CVE-2026-62870 immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Excel and Office

Get an email when a new Excel and Office advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-04
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2625

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-62870coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Microsoft Excel

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories