THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-64955 (MEDIUM 6.1) — When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.  Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data ex

[NVD] CVE-2026-64955 (MEDIUM 6.1) — When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.  Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data ex

mednvdPublished 2026-08-12

CVE-2026-64955 CVSS: 6.1 MEDIUM Published: 2026-08-12T10:17:20.310

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. 

Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.

It is not clear if the vulnerability is actu

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64955