KB5002718 is a March 2026 security update for Microsoft Excel 2016 that patches critical vulnerabilities including remote code execution and information disclosure flaws. This update applies to both 32-bit and 64-bit editions of Excel 2016 and is delivered through Microsoft Update.

KB5002718 — Security Update for Microsoft Excel 2016
KB5002718 is a security update released on March 10, 2026, that addresses multiple vulnerabilities in Microsoft Excel 2016, including remote code execution and information disclosure flaws affecting both 32-bit and 64-bit editions.
KB5002718 is a security update released on March 10, 2026, that addresses multiple vulnerabilities in Microsoft Excel 2016, including remote code execution and information disclosure flaws affecting both 32-bit and 64-bit editions.
In This Article
- Issue Description
- Root Cause
- 1Fixes remote code execution vulnerability in Excel file parsing (CVE-2026-0847)
- 2Resolves information disclosure vulnerability in formula processing (CVE-2026-0848)
- 3Patches memory corruption issue in chart object handling (CVE-2026-0849)
- 4Strengthens security for external data connections and queries
- Installation
- Known Issues
- Frequently Asked Questions
Applies to
Issue Description
Issue Description
This security update addresses several vulnerabilities in Microsoft Excel 2016 that could allow attackers to execute arbitrary code or access sensitive information:
- Remote Code Execution: Specially crafted Excel files could allow an attacker to execute code in the context of the current user when opened
- Information Disclosure: Malicious Excel documents could expose memory contents, potentially revealing sensitive data
- Memory Corruption: Improper handling of objects in memory could lead to application crashes or code execution
- Parsing Vulnerabilities: Malformed Excel file structures could trigger buffer overflows or other memory safety issues
Root Cause
Root Cause
The vulnerabilities stem from improper input validation and memory management in Excel's file parsing engine. Specifically, the application fails to properly validate certain data structures within Excel files, leading to buffer overflows and memory corruption issues. Additionally, insufficient bounds checking when processing embedded objects and formulas creates opportunities for remote code execution attacks.
Fixes remote code execution vulnerability in Excel file parsing (CVE-2026-0847)
This update patches a critical remote code execution vulnerability in Excel's file parsing engine. The fix implements proper bounds checking and input validation when processing Excel file headers and embedded objects. This prevents attackers from exploiting malformed Excel files to execute arbitrary code on the target system.
Technical Details:
- Enhanced validation of Excel file structure elements
- Improved memory allocation and deallocation routines
- Strengthened parsing of embedded OLE objects
- Additional security checks for macro-enabled workbooks
Resolves information disclosure vulnerability in formula processing (CVE-2026-0848)
Addresses an information disclosure vulnerability where specially crafted formulas could cause Excel to read beyond allocated memory boundaries, potentially exposing sensitive data from other applications or system memory.
Technical Details:
- Corrected memory boundary checks in formula evaluation engine
- Enhanced validation of cell references and range operations
- Improved handling of external data connections
- Strengthened protection against memory disclosure attacks
Patches memory corruption issue in chart object handling (CVE-2026-0849)
Fixes a memory corruption vulnerability in Excel's chart rendering component that could be exploited through malicious chart objects embedded in Excel files. The vulnerability could lead to application crashes or potential code execution.
Technical Details:
- Improved validation of chart data structures
- Enhanced memory management for chart rendering operations
- Corrected buffer size calculations for chart elements
- Additional safety checks for chart data series processing
Strengthens security for external data connections and queries
Enhances security controls for external data connections, web queries, and database connections to prevent unauthorized data access and potential security bypasses through malicious connection strings.
Technical Details:
- Improved validation of connection string parameters
- Enhanced authentication checks for external data sources
- Strengthened URL validation for web queries
- Additional security warnings for potentially unsafe connections
Installation
Installation
KB5002718 is available through multiple installation methods:
Microsoft Update (Recommended)
The update is automatically delivered through Microsoft Update for systems with automatic updates enabled. Installation typically occurs during the next scheduled update cycle.
Microsoft Update Catalog
Manual download is available from the Microsoft Update Catalog for enterprise deployment:
- File Size: Approximately 85 MB (32-bit), 95 MB (64-bit)
- Restart Required: No (Excel restart recommended)
- Installation Time: 5-10 minutes
Enterprise Deployment
System administrators can deploy this update through:
- Windows Server Update Services (WSUS)
- Microsoft System Center Configuration Manager (SCCM)
- Microsoft Intune
- Group Policy
Prerequisites
Before installing KB5002718, ensure the following requirements are met:
- Microsoft Excel 2016 (32-bit or 64-bit edition) must be installed
- Minimum 500 MB free disk space
- Administrative privileges for installation
- Close all Office applications before installation
Known Issues
Known Issues
The following issues have been reported after installing KB5002718:
Installation Issues
- Error 0x80070643: Installation may fail if Office applications are running. Close all Office programs and retry installation.
- Error 0x80240017: Insufficient disk space. Ensure at least 500 MB free space is available on the system drive.
Post-Installation Issues
- Slow Excel Startup: Some users may experience slightly longer Excel startup times due to enhanced security checks. This is expected behavior.
- External Data Connection Prompts: Users may see additional security prompts when opening files with external data connections. This is an intended security enhancement.
- Macro Security Warnings: Enhanced macro security may result in additional warning dialogs for macro-enabled workbooks.
Workarounds
- For startup performance issues, disable unnecessary add-ins through File > Options > Add-ins
- Configure trusted locations for frequently used files with external connections
- Update macro security settings through File > Options > Trust Center if needed
Overview
KB5002718 is a critical security update for Microsoft Excel 2016 released on March 10, 2026. This update addresses multiple high-severity vulnerabilities that could allow remote code execution, information disclosure, and memory corruption attacks through specially crafted Excel files.
Affected Systems
This security update applies to the following Microsoft Excel 2016 editions:
| Product | Edition | Architecture | Status |
|---|---|---|---|
| Microsoft Excel 2016 | Standard | 32-bit | Affected |
| Microsoft Excel 2016 | Standard | 64-bit | Affected |
| Microsoft Excel 2016 | Professional Plus | 32-bit | Affected |
| Microsoft Excel 2016 | Professional Plus | 64-bit | Affected |
Security Vulnerabilities Addressed
This update resolves four critical security vulnerabilities:
CVE-2026-0847: Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly validate input. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user. Exploitation requires user interaction, typically opening a malicious Excel file.
CVE-2026-0848: Information Disclosure Vulnerability
An information disclosure vulnerability exists when Excel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system. Exploitation could occur through specially crafted formulas or external data connections.
CVE-2026-0849: Memory Corruption Vulnerability
A memory corruption vulnerability exists in Excel's chart rendering engine. An attacker could exploit this vulnerability by convincing a user to open a specially crafted file containing malicious chart objects, potentially leading to code execution or application crashes.
Enhanced Security for External Connections
This update also strengthens security controls for external data connections, web queries, and database connections to prevent potential security bypasses and unauthorized data access.
Installation Requirements
Before installing KB5002718, verify the following system requirements:
- Operating System: Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, or Windows Server 2022
- Microsoft Excel 2016: Any edition (32-bit or 64-bit)
- Disk Space: Minimum 500 MB free space
- User Rights: Administrative privileges required for installation
- Network: Internet connection for automatic updates
Deployment Methods
Automatic Updates
For most users, KB5002718 will be automatically downloaded and installed through Microsoft Update. The update is classified as Important and will be included in the regular update cycle.
Manual Installation
Enterprise administrators can manually deploy this update using:
- Microsoft Update Catalog downloads
- Windows Server Update Services (WSUS)
- System Center Configuration Manager
- Microsoft Intune for cloud-managed devices
Verification Commands
To verify successful installation, use the following PowerShell command:
Get-HotFix -Id KB5002718Or check through Control Panel > Programs and Features > View installed updates.
Security Impact
Installing KB5002718 provides the following security improvements:
- Prevents Remote Code Execution: Blocks exploitation of file parsing vulnerabilities
- Stops Information Disclosure: Prevents unauthorized memory access through malicious formulas
- Eliminates Memory Corruption: Fixes chart rendering vulnerabilities
- Strengthens Data Connections: Enhanced validation for external data sources
Compatibility and Testing
Microsoft has tested KB5002718 for compatibility with common Excel usage scenarios, including:
- Standard spreadsheet operations and formulas
- Chart creation and editing
- External data connections and queries
- Macro-enabled workbooks
- Add-in compatibility
- Integration with other Office applications
No significant compatibility issues have been identified during testing. However, organizations should test the update in their specific environment before widespread deployment.
Frequently Asked Questions
What does KB5002718 resolve?
Which systems require KB5002718?
Is KB5002718 a security update?
What are the prerequisites for KB5002718?
Are there known issues with KB5002718?
References (3)
About the Author
Discussion
Share your thoughts and insights
You must be logged in to comment.
Related KB Articles

KB5002846 — Security Update for Office Online Server
KB5002846 is a March 2026 security update that addresses multiple vulnerabilities in Office Online Server, including remote code execution and information disclosure flaws affecting document rendering and authentication components.

KB5002849 — Security Update for Microsoft Excel 2016
KB5002849 is a security update for Microsoft Excel 2016 that addresses critical vulnerabilities in file processing and memory handling, affecting both 32-bit and 64-bit editions of Excel 2016.

KB5002843 — Security Update for SharePoint Server Subscription Edition
KB5002843 is a March 2026 security update that addresses multiple vulnerabilities in SharePoint Server Subscription Edition, including remote code execution and elevation of privilege issues.

KB5002848 — Security Update for Microsoft Word 2016
KB5002848 is a security update released March 10, 2026, that addresses multiple vulnerabilities in Microsoft Word 2016, including remote code execution and information disclosure flaws affecting both 32-bit and 64-bit editions.