Skip to content

CVE-2025-60727

CVE

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 11, 2025
Last Seen
June 29, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A newly disclosed remote code execution (RCE) vulnerability, tracked as CVE-2025-60727, affects Microsoft 365 Apps, allowing attackers to execute arbitrary code through malicious Excel documents. This vulnerability arises from an out-of-bounds read condition in Excel's file-parsing mechanism, leadin...

In December 2025, Adobe released five bulletins addressing 139 unique vulnerabilities as part of its security updates. This follows the November updates, where Adobe addressed 29 unique CVEs across several products. Microsoft also provided updates during this final patch Tuesday of the year.

Public Exploits

Checking GitHub for proof-of-concept code…