# Microsoft Office RCE flaw CVE-2026-62870

Published: 2026-08-03 · Severity: medium
Canonical: https://vorant.io/reports/3cb522b9-7117-53dc-8c90-86f5566b4f50/microsoft-office-rce-flaw-cve-2026-62870

> A remote code execution vulnerability in Microsoft Office and Excel products has been disclosed by CERT-FR with a Microsoft patch available.

CERT-FR issued an advisory regarding CVE-2026-62870, a remote code execution vulnerability affecting multiple Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Office 2019, and Office LTSC 2021/2024 across both 32-bit and 64-bit editions. The vulnerability could allow an attacker to execute arbitrary code on affected systems.

No evidence of active exploitation is mentioned in the advisory. Microsoft has published a security bulletin with corrective patches, and CERT-FR recommends organizations apply the vendor-provided fixes to remediate the vulnerability across all affected Office product lines.

## Mentioned in this report

- Vulnerabilities: CVE-2026-62870

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0961

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3cb522b9-7117-53dc-8c90-86f5566b4f50/microsoft-office-rce-flaw-cve-2026-62870.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
