LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-0238: Microsoft Office Remote Code Execution

RBRecent Breaches Vulnerability Intelligence·Apr 14, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-0238 to its Known Exploited Vulnerabilities catalog on Apr 14, 2026, with a federal patch deadline of Apr 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that…

This vulnerability is a remote code execution issue affecting Microsoft Office Excel. An attacker can gain complete control of an affected system when a user opens a specially crafted Excel file that includes a malformed object. It matters because the flaw allows arbitrary code execution, which can lead to full system compromise without further user interaction beyond opening the file.

How it works

The weakness falls under CWE-94, improper control of generation of code. An attacker supplies a malformed object inside an Excel file that the application processes without sufficient validation, resulting in execution of attacker-controlled code on the target system.

Am I affected? How to find it in your systems

This affects Microsoft Office installations that include Excel. Inventory systems by querying software asset management tools or endpoint management platforms for the presence of Excel components. Prioritize review of any deployments that routinely handle files from external or untrusted sources.

How to remediate

Apply mitigations per vendor instructions as the first action. After the update is deployed, reduce attack surface for this class of weakness by restricting Excel file handling to trusted sources and enforcing least-privilege execution contexts for Office applications.

If you can't patch immediately

Follow applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Until the update can be applied, isolate affected systems on segmented networks and monitor for anomalous behavior.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-94
Added to CISA KEVApr 14, 2026
Federal patch deadlineApr 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities