CVE-2026-45459 is a protection-mechanism failure in Microsoft Office Excel. The flaw permits a malicious workbook to bypass intended Excel security controls, including behavior described as bypassing Trusted Records and Office Protected View. The documented Python in Excel technique abuses a Python rich-value web-image object: when the workbook is opened, Excel can silently retrieve an attacker-selected remote resource without the intended additional approval. A subsequent Python cell can transfer the retrieved data from the client into the otherwise network-isolated Python in Excel execution environment. Microsoft also characterizes successful exploitation as causing a malicious Office file to open in editing mode rather than Protected View.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft Excel Trusted Records control bypass that can cause a victim machine to silently retrieve a URL and upload data to the network-isolated Python in Excel container.
A vulnerability in Microsoft Excel’s Python in Excel feature that bypasses the Trusted Records protection by abusing a Python rich-value/web-image result object, causing the Excel client to silently fetch attacker-controlled URLs and enabling data to be uploaded into the isolated container.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.