Known Vulnerabilities for Excel by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Excel" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40576 json | excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in exc... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-39424 json | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable to Im... | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-32199 json | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-32198 json | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-32197 json | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-32189 json | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-32188 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-26133 json | Not Provided | 2026-03-16 | 2026-04-09 | |
| CVE-2026-2830 json | The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected ... | Not Provided | 2026-03-06 | 2026-04-08 |
| CVE-2026-1389 json | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct Obje... | Not Provided | 2026-01-28 | 2026-04-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Excel | 97 | |||
| Application | Microsoft | Excel | 97 | |||
| Application | Microsoft | Excel | 97 | |||
| Application | Microsoft | Excel | 97 | |||
| Application | Microsoft | Excel | 97 | |||
| Application | Microsoft | Excel | 97 | |||
| Application | Microsoft | Excel | 95 | |||
| Application | Microsoft | Excel | 4.0 | |||
| Application | Microsoft | Excel | 3.0 | |||
| Application | Microsoft | Excel | 2019 | |||
| Application | Microsoft | Excel | 2019 | |||
| Application | Microsoft | Excel | 2019 | |||
| Application | Microsoft | Excel | 2016 | |||
| Application | Microsoft | Excel | 2016 | |||
| Application | Microsoft | Excel | 2016 | |||
| Application | Microsoft | Excel | 2016 | |||
| Application | Microsoft | Excel | 2016 | |||
| Application | Microsoft | Excel | 2013 | |||
| Application | Microsoft | Excel | 2013 | |||
| Application | Microsoft | Excel | 2013 |