Microsoft published a long series of security advisories for remote code execution vulnerabilities affecting core Office components, with the largest concentration in Excel and Word. The disclosures include Excel flaws such as CVE-2024-49026, CVE-2024-49069, CVE-2025-21362, CVE-2025-21381, CVE-2025-21387, CVE-2025-24082, CVE-2025-62553, CVE-2026-26107, CVE-2026-26109, CVE-2026-26112, and CVE-2026-40359, alongside Word issues including CVE-2025-24077, CVE-2025-24078, CVE-2025-47170, CVE-2025-49700, CVE-2025-59222, CVE-2026-23657, and CVE-2026-33095. Microsoft also listed related RCE bugs in Microsoft Office (CVE-2025-21392), PowerPoint (CVE-2025-54908), Inbox COM Objects (Global Memory) (CVE-2025-58730), and the Visual Studio Code Python Extension (CVE-2025-49714).
One of the few entries with technical detail, CVE-2026-40359, describes an Important Excel use-after-free flaw (CWE-416) with a CVSS 3.1 score of 7.8 that can let an attacker execute code if a user opens a malicious Office file. Microsoft said the bug was not publicly disclosed, not exploited in the wild, and less likely to be exploited at the time of publication, adding that the Preview Pane is not an attack vector and that a fix is available. Taken together, the advisories show Microsoft continuing to address document-driven code execution risks across Office products, where successful exploitation generally depends on user interaction with crafted files rather than direct network exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
35 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-12, Microsoft disclosed CVE-2026-40359, an Important Excel remote code execution vulnerability caused by a use-after-free flaw. Microsoft said exploitation required user interaction to open a malicious Office file, the Preview Pane was not an attack vector, no in-the-wild exploitation or prior public disclosure was known, and a fix was available; the issue was credited to f4 and Zhiniang Peng of HUST.
On 2026-04-14, Microsoft published a Security Update Guide entry for CVE-2026-32197, an Important Microsoft Excel remote code execution vulnerability caused by a use-after-free flaw. Microsoft said exploitation required user interaction to open a malicious Office file, the Preview Pane was not an attack vector, no public disclosure or in-the-wild exploitation was known, and a fix was available.
On 2026-04-14, Microsoft published a Security Update Guide entry for CVE-2026-32189, an Important Microsoft Excel remote code execution vulnerability caused by a use-after-free flaw. Microsoft said exploitation required user interaction to open a malicious Office file, the Preview Pane was not an attack vector, no public disclosure or in-the-wild exploitation was known, and a fix was available.
On 2026-04-14, Microsoft disclosed CVE-2026-23657 and CVE-2026-33095, both Microsoft Word remote code execution vulnerabilities. These entries were part of the April 2026 update cycle.
On 2026-03-10, Microsoft published Security Update Guide entries for CVE-2026-26107, CVE-2026-26109, and CVE-2026-26112. All three were identified as Microsoft Excel remote code execution vulnerabilities.
Microsoft released a Security Update Guide entry for CVE-2025-62553, a Microsoft Excel remote code execution vulnerability. The disclosure was published on 2025-12-09.
On 2025-10-14, Microsoft published a Security Update Guide entry for CVE-2025-59224, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's October 2025 release cycle.
On 2025-10-14, Microsoft published a Security Update Guide entry for CVE-2025-59223, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's October 2025 release cycle.
On 2025-10-14, Microsoft published CVE-2025-59222 affecting Word and CVE-2025-58730 affecting Inbox COM Objects (Global Memory). Both were listed as remote code execution vulnerabilities.
Microsoft released a Security Update Guide entry for CVE-2025-54904, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure was published on 2025-09-09 as part of Microsoft's September 2025 update cycle.
Microsoft disclosed CVE-2025-54908 as a Microsoft PowerPoint remote code execution vulnerability in the Security Update Guide. The entry was published on 2025-09-09.
On 2025-07-08, Microsoft published a Security Update Guide entry for CVE-2025-49711, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's July 2025 release cycle.
On 2025-07-08, Microsoft published entries for CVE-2025-49700 affecting Microsoft Word and CVE-2025-49714 affecting the Visual Studio Code Python Extension. Both were classified as remote code execution vulnerabilities.
Microsoft released a Security Update Guide entry for CVE-2025-47170, a Microsoft Word remote code execution vulnerability. The disclosure was published on 2025-06-10.
Microsoft released a Security Update Guide entry for CVE-2025-47173, identifying it as a Microsoft Office remote code execution vulnerability. The disclosure was published on 2025-06-10 as part of Microsoft's June 2025 update cycle.
On 2025-03-11, Microsoft published a Security Update Guide entry for CVE-2025-24079, identifying it as a Microsoft Word remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's March 2025 release cycle.
On 2025-03-11, Microsoft published a Security Update Guide entry for CVE-2025-24081, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's March 2025 release cycle.
On 2025-03-11, Microsoft published Security Update Guide entries for CVE-2025-24077 and CVE-2025-24078 in Word and CVE-2025-24082 in Excel. The disclosures added multiple Office document-handling remote code execution issues to the March 2025 updates.
On 2025-02-11, Microsoft published a Security Update Guide entry for CVE-2025-21397, identifying it as a Microsoft Office remote code execution vulnerability. The disclosure adds another Office-related RCE issue to Microsoft's February 2025 release cycle.
On 2025-02-11, Microsoft published a Security Update Guide entry for CVE-2025-21394, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's February 2025 release cycle.
On 2025-02-11, Microsoft disclosed CVE-2025-21381 and CVE-2025-21387 affecting Excel, along with CVE-2025-21392 affecting Microsoft Office. These entries indicate multiple remote code execution vulnerabilities addressed in the February 2025 release cycle.
On 2025-02-11, Microsoft published a Security Update Guide entry for CVE-2025-21386, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's February 2025 release cycle.
On 2025-02-11, Microsoft published a Security Update Guide entry for CVE-2025-21390, identifying it as a Microsoft Excel remote code execution vulnerability. This adds another Office document-handling RCE issue to Microsoft's February 2025 release cycle.
On 2025-01-14, Microsoft published a Security Update Guide entry for CVE-2025-21361, identifying it as a Microsoft Outlook remote code execution vulnerability. The disclosure adds another Office-related RCE issue to Microsoft's January 2025 release cycle.
On 2025-01-14, Microsoft published a Security Update Guide entry for CVE-2025-21354, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's January 2025 release cycle.
On 2025-01-14, Microsoft published a Security Update Guide entry for CVE-2025-21356, identifying it as a Microsoft Office Visio remote code execution vulnerability. The disclosure adds another Office-related RCE issue to Microsoft's January 2025 release cycle.
On 2025-01-14, Microsoft published a Security Update Guide entry for CVE-2025-21366, identifying it as a Microsoft Access remote code execution vulnerability. The disclosure adds another Office-related RCE issue to Microsoft's January 2025 release cycle.
On 2025-01-14, Microsoft published a Security Update Guide entry for CVE-2025-21395, identifying it as a Microsoft Access remote code execution vulnerability. The disclosure adds another Office-related RCE issue to Microsoft's January 2025 release cycle.
On 2025-01-14, Microsoft published Security Update Guide entries for CVE-2025-21362, an Excel remote code execution vulnerability. This marks a January Patch Tuesday disclosure affecting Microsoft Office components.
Microsoft published a Security Update Guide entry for CVE-2024-49069, identifying another Microsoft Excel remote code execution vulnerability. The disclosure appeared on 2024-12-10.
On 2024-11-12, Microsoft published a Security Update Guide entry for CVE-2024-49029, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's November 2024 update cycle.
On 2024-11-12, Microsoft published a Security Update Guide entry for CVE-2024-49028, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure adds another Office document-handling RCE issue to Microsoft's November 2024 update cycle.
On 2024-11-12, Microsoft published a Security Update Guide entry for CVE-2024-49032, identifying it as a Microsoft Office Graphics remote code execution vulnerability. The disclosure adds another Office-related RCE issue to Microsoft's November 2024 update cycle.
Microsoft published a Security Update Guide entry for CVE-2024-49027, identifying it as a Microsoft Excel remote code execution vulnerability. The disclosure was published on 2024-11-12 as part of Microsoft's November 2024 update cycle.
Microsoft released a Security Update Guide advisory for CVE-2024-49026, a Microsoft Excel remote code execution vulnerability. The advisory was published on 2024-11-12.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
49 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.