Microsoft 365 Apps RCE Vulnerability Exploited Using a Malicious Excel File
Microsoft has disclosed a critical remote code execution vulnerability in its Office ecosystem that can be exploited through a malicious Excel file. The vulnerability, tracked as CVE-2025-60727, affects multiple versions of Microsoft Office and underscores the continued risk posed by document-based attack techniques commonly used in phishing campaigns. The issue is classified as an out-of-bounds […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
