← All Advisories

Microsoft Excel's Use After Free Vulnerability Lets Remote Attackers Execute Arbitrary Code via a Specially Crafted Workbook

Last refreshed2026-09-27

Status: UPDATED  |  Advisory ID: CVE-2026-62870

Key Details

CVECVE-2026-62870
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsMicrosoft Microsoft 365 Apps, Microsoft Excel, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024
Classified asCWE-416 (Use After Free)
Exploitation prediction (EPSS)0.82% probability of exploitation in the next 30 days (55% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MicrosoftMicrosoft 365 Apps
MicrosoftExcel
MicrosoftOffice 2019
MicrosoftOffice 2021
MicrosoftOffice 2024
SubsystemsGeneral OT
SectorsMultiple

What to Know

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

What to Do

Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-62870
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-62870
Vendor advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62870