Microsoft Office RCE flaw CVE-2026-62870
A remote code execution vulnerability in Microsoft Office and Excel products has been disclosed by CERT-FR with a Microsoft patch available.
CERT-FR issued an advisory regarding CVE-2026-62870, a remote code execution vulnerability affecting multiple Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Office 2019, and Office LTSC 2021/2024 across both 32-bit and 64-bit editions. The vulnerability could allow an attacker to execute arbitrary code on affected systems.
No evidence of active exploitation is mentioned in the advisory. Microsoft has published a security bulletin with corrective patches, and CERT-FR recommends organizations apply the vendor-provided fixes to remediate the vulnerability across all affected Office product lines.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0961
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free