Old Excel RCE Returns to CISA’s Exploited List

A 17-year-old Excel flaw is back in active use, and the standard response of treating it as legacy risk misses the point: old document bugs still let attackers turn trusted files into code execution and phishing bait. Once a victim opens the file, the trust signal is already working for the attacker. CISA added CVE-2009-0238 to its Known Exploited Vulnerabilities catalog after confirming active exploitation and gave federal civilian agencies two weeks to patch. Microsoft says the issue affects Excel 2000 SP3, 2002 SP3, 2003 SP3, 2007 SP1, Excel Viewer 2003 Gold and SP3, Excel Viewer, the Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, and Excel for Mac 2004 and 2008. The forward risk is not just code execution on old installs. The flaw can also help attackers spoof trusted content, which makes malicious documents harder to spot when defenders rely on metadata or file appearance.

Part of the PlainSec briefing for 2026-04-16

Sources