CVE-2026-45459PoC(microsoft / 365_apps)

MEDIUMCVSS 3.3 · LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for microsoft 365_apps systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • microsoft_365
  • office_2021
  • office_2024

Threat summary

  • Public PoC and exploit tooling are both present
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-08-07); latest day: 2
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
365_appsmicrosoft_365office_2021office_2024

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-08-07: 2Mentions · 2026-08-08: 1Mentions · 2026-08-09: 1Mentions · 2026-09-16: 2PoC Mentioned / Linked · 2026-08-07: 2PoC Mentioned / Linked · 2026-08-08: 1PoC Mentioned / Linked · 2026-09-16: 1Exploit Tool / Code · 2026-08-07: 1Exploit Tool / Code · 2026-08-08: 1Technical Details · 2026-08-07: 2Technical Details · 2026-08-08: 1Technical Details · 2026-09-16: 108-0708-0808-0909-16
Signal classification3 categories
PoC
350.0%
Disclosure
233.3%
Exploit
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-072
Exploit1PoC1
2026-08-081
PoC1
2026-08-091
Disclosure1
2026-09-162
Disclosure1PoC1
Full discourse6 posts
  • Panos Gkatziroulis 🦄@ipurple
    Disclosure

    From Square Root to /root: Escalating Privileges in Azure Containers with Python in Excel https://www.safebreach.com/blog/python-in-excel-vulnerability-root-escalation-cve-2026-45459/

    Post summary

    The linked blog post announces a new CVE (2026‑45459) that allows privilege escalation in Azure containers via Python in Excel, but the excerpt provides no PoC, exploit code, active exploitation evidence, patch info, or technical specifics.

    24019122.2K
    27.2K followersView on X
  • SafeBreach@safebreach
    PoC

    Read the research and see PoC here: https://www.safebreach.com/blog/python-in-excel-vulnerability-root-escalation-cve-2026-45459/

    Post summary

    The post points to a PoC for CVE‑2026‑45459 describing a Python in Excel root‑escalation flaw, offering no exploit code, patch guidance, or evidence of active exploitation.

    02042109
    2.5K followersView on X
  • SafeBreach@safebreach
    Disclosure

    Isolation is not the same thing as security. Security Research Team Lead, Ron Ben Yizhak, went from restricted user to root inside the Azure container behind Python in Excel—and found CVE-2026-45459 along the way. How isolated is "isolated," really? Get the link in the comments. https://t.co/fQLCpxpnCi

    Post summary

    The post discloses the discovery of CVE‑2026‑45459 by a security researcher, offering no PoC, exploit tool, active exploitation, or patch guidance. It is therefore classified as a disclosure of a new vulnerability.

    22040186
    2.5K followersView on X
  • DirectoryRanger@DirectoryRanger
    PoC

    From Square Root to /root: Escalating Privileges in Azure Containers with Python in Excel https://www.safebreach.com/blog/python-in-excel-vulnerability-root-escalation-cve-2026-45459/

    Post summary

    The post discusses CVE‑2026‑45459, presenting a proof‑of‑concept exploit that elevates privileges in Azure containers via Python in Excel, but it does not report active exploitation or provide a patch.

    000251.6K
    37.2K followersView on X
  • Ron BY@RonB_Y
    PoC

    Following my @defcon talk, the blog post about the vulnerabilities I found in the cloud environment of Python in Excel is now public on the @safebreach website. https://www.safebreach.com/blog/python-in-excel-vulnerability-root-escalation-cve-2026-45459/ Also, we published tools for the community to continue this research. https://github.com/SafeBreach-Labs/FromSquareRootToSlashRoot

    Post summary

    A blog post reveals CVE-2026-45459, a root‑escalation flaw in Python‑in‑Excel, and SafeBreach has released PoC tools for the community to study it.

    01041669
    409 followersView on X
  • SafeBreach@safebreach
    Exploit

    An Excel math function became a path to root in Microsoft's cloud. SafeBreach Labs' Ron Ben Yizhak escalated to root inside the "isolated" Azure containers behind Python in Excel—then bypassed a core Excel security control (CVE-2026-45459). Research here: https://hubs.ly/Q04shBQM0 https://t.co/KIUIWcqCiQ

    Post summary

    SafeBreach Labs demonstrated root escalation inside Azure containers via an Excel math function (CVE-2026-45459), providing research links but no explicit exploit code or patch information.

    01020139
    2.5K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftmicrosoft_365-macos-
Appmicrosoftoffice_2021-macos-
Appmicrosoftoffice_2024--x64
Appmicrosoftoffice_2024--x86
Appmicrosoftoffice_2024-macos-

Explore more