SafeBreach Labs disclosed weaknesses in Microsoft’s Python in Excel feature that enabled privilege escalation in its Azure-hosted execution containers. A symbolic-link flaw in the file-upload mechanism allowed an unprivileged jovyan container user to become root, exposing an internal configuration file containing backend architectural details and hostnames. The researcher also found that Python in Excel container images could be pulled anonymously and that some builds included an undocumented AI-agent framework.
A separate flaw, tracked as CVE-2026-45459, bypassed Excel’s Trusted Records protection through a Python rich-value web-image object. An attacker could cause a victim’s Excel client to silently retrieve an attacker-controlled URL and upload the retrieved data to the nominally network-isolated Python container. Microsoft received the reports through responsible disclosure, patching the container escalation path in March 2026 and the Excel-side issue on June 9, 2026; the findings were later presented at DEF CON 34.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft patched CVE-2026-45459 to prevent Excel from initiating a network connection based on a web-image object returned by Python code.
SafeBreach separately reported an Excel-side Trusted Records bypass that used a Python rich-value web-image object to silently fetch an attacker-controlled URL and upload fetched data into the isolated container. Microsoft assigned the issue CVE-2026-45459.
Microsoft released version 16.0.19828.43251 to resolve the container privilege-escalation path, including symlink checks across relevant file operations.
SafeBreach reported a symbolic-link privilege-escalation flaw, anonymous container-image access, configuration exposure, and undocumented AI-framework findings in Microsoft’s Python in Excel Azure environment. The flaw could elevate the unprivileged jovyan user to root within a container.
Ron Ben Yizhak publicly presented the Python in Excel container-isolation and Trusted Records bypass research at DEF CON 34.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.