THREAT OPS › Threat News › [NVD] CVE-2026-64955 (MEDIUM 6.1) — When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.
Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data ex
[NVD] CVE-2026-64955 (MEDIUM 6.1) — When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data ex
CVE-2026-64955 CVSS: 6.1 MEDIUM Published: 2026-08-12T10:17:20.310
When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.
Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.
It is not clear if the vulnerability is actu
Indicators of compromise
- CVE-2026-64955cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64955