April 13, 2026 · Applied Cybernetics Group
CVE-2012-1854 — Microsoft Visual Basic for Applications (VBA)
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
- Added to KEV
2026-04-13- Federal due date
2026-04-27- Vendor
- Microsoft
- Product
- Visual Basic for Applications (VBA)
- EPSS
- 87.7th percentile (score 0.034, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2012-1854
CISA short description
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.