
- CISA adds 18‑year‑old Excel flaw (CVE‑2009‑0238) to KEV catalog
- Vulnerability enables RCE via malicious Excel files, patched long ago
- Outdated systems still at risk; agencies ordered to patch by April 28
Incredible as it may sound, there are still systems out there vulnerable to 18-year-old Microsoft Excel vulnerabilities, and unsurprisingly, cybercriminals are taking advantage of that fact.