[CIVN-2026-0020] Multiple Remote Code Execution Vulnerabilities in Microsoft Excel

By Published On: January 15, 2026

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Remote Code Execution Vulnerabilities in Microsoft Excel 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Microsoft Office
Overview
Multiple vulnerabilities have been reported in Microsoft Office Excel which could allow an attacker to execute arbitrary code on the affected system.
 
Target Audience:
All end-user organizations and individuals managing Microsoft Excel.
Risk Assessment:
High risk of remote code execution and system compromise.
Impact Assessment:
Potential for unauthorized access, data theft, or execution of malicious code.
Description
Microsoft Excel is a spreadsheet application which allows users to organize, analyze, and visualize data using formulas, charts, and pivot tables. It is used for tasks ranging from simple calculations to complex financial and statistical modeling.
These vulnerabilities exist in Microsoft Excel due to memory handling flaws. A remote attacker could exploit these vulnerabilities by enticing the target user to execute a specially crafted Excel file. Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code resulting in system compromise, or data theft.
Solution
Apply appropriate security updates as mentioned in
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20955
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20957
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20955
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20957
References
 
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20955
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20957
CVE Name
CVE-2026-20955
CVE-2026-20957
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmlo9WAACgkQ3jCgcSdc
ys8YIw//ek1KmC9ERhxD58GBaKo8Y2XCL2nDx4Cg+sgRCTJGRCRxFBJolhys8EmT
3ajMmM00uriySmeFc+pSb2IkUtld46a2WUsuJZZx+L4+f7GgOvTqIWYKBh+9G6JQ
w4RpENVkL/75nO68JQCHyJghEXzhaMtZkq6VF17kBYzvmo1XFcqFdyPrJXzmbHSy
bqfOF3FlgVhDNlNF3P/BUEI/HnwQYhuKEzcR/bpM1v7q1rpPjAb7w+1dpeXzInfe
8VtSRpBW5yQzB1TXnSvm9ZkvHIXbLRMkXbWKPay52IwSzyQQ3lOeim/ritQbqsZc
2qCUZRgxTxg6YY5QogDnLG8jt8DgyS+uPG+YkwYVbOgldOabQvOY1UoFuqbi18eb
XXcg3oD9n50o3X/kHqqMHXkd3bn7KKM9k57ZA1H2CUKgAM/IutuzMViJqDzM04xt
One2IuY1StHguKByLeB8c982jYlx3Lf+u3SB0gcoXRlyDHr6+sqoRTbKX93CSGm2
eELU6+C1OagkWdGbuZfOF4lnKb6v3ubVL/dvCZZQyRScHBZ5k8Dx+LPqh5rrmWXH
Fg/Rzjf87WPGzQ2Vy+UAY2CKz2+4CKStXmSCTrqfiDqdmLOO2mBDJL3gNChr8NuS
6kS0DL0Dn1kflpYiOKwMxYHVu+kehJ97aiiO+WdJFFdJAj4oAqM=
=YiRc
—–END PGP SIGNATURE—–

Share this article