« Back to list

Microsoft

Microsoft Excel: vulnerabilities and CVEs

Microsoft Excel has 505 published vulnerabilities, 141 of them in the last 12 months. 2 are rated critical and 6 are listed by CISA as actively exploited.

CVEs505
Last 12 months141
Critical2
Actively exploited6

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2009-0238High (8.8)43%⚠ Active exploitationFeb 25, 2009
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office…
CVE-2007-0671High (8.8)43%⚠ Active exploitationFeb 3, 2007
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as…
CVE-2019-1297High (8.8)22%⚠ Active exploitationSep 11, 2019
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
CVE-2009-3129High (7.8)84%⚠ Active exploitationNov 11, 2009
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office…
CVE-2016-7262High (7.8)58%⚠ Active exploitationDec 20, 2016
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted…
CVE-2021-42292High (7.8)43%⚠ Active exploitationNov 10, 2021
Microsoft Excel Security Feature Bypass Vulnerability

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-85875Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81960High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81959High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81958Medium (5.5)0.54%—Sep 8, 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81957High (7.8)0.47%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81956High (7.8)0.47%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81954High (7.8)0.47%—Sep 8, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81953High (7.8)0.47%—Sep 8, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81951High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81950High (7.8)0.47%—Sep 8, 2026
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81949High (7.8)0.47%—Sep 8, 2026
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81948High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81947High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81401Medium (5.5)0.54%—Sep 8, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81400Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81399Medium (5.5)0.54%—Sep 8, 2026
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81398High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81397High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81396High (7.8)0.47%—Sep 8, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81395Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81394Medium (5.5)0.55%—Sep 8, 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81393Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81392Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81391Medium (5.5)0.54%—Sep 8, 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81390Medium (5.5)0.54%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81389High (7)0.37%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81388High (7.8)0.47%—Sep 8, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81387Medium (5.5)0.55%—Sep 8, 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81386High (7.8)0.47%—Sep 8, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-78518High (8.8)0.86%—Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1203 Exploitation for Client Execution3
  2. T1059 Command and Scripting Interpreter2
  3. T1059.005 Visual Basic1
  4. T1204.002 Malicious File1
  5. T1499.004 Application or System Exploitation1
  6. T1566 Phishing1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft