Is each file being executable for Linux your exact concern? Do you want all regular files to be effectively non-executable? If so, consider placing the whole share under its own mountpoint and mount with
noexec. A determined Linux user may be able to execute chosen files regardless, but this is true also for files with -x.