CVE-2026-81386
massHeap Buffer Overflow in Microsoft Excel Enables Local Code Execution
CVE-2026-81386 is a heap-based buffer overflow (CWE-122) in the Excel component of Microsoft Office. The CVSS vector indicates a local attack vector with user interaction required, meaning an attacker must get a local user to trigger the flaw, consistent with opening specially crafted spreadsheet content that corrupts Excel's heap memory. Successful exploitation lets the unauthorized attacker execute code in the context of the local user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). Anyone running Excel within Microsoft 365 Apps or the Office 2016, 2019, 2021, and 2024 releases is potentially affected. There is no evidence of active exploitation: no public proof of concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (29th percentile).
What to do: Apply Microsoft's current security updates for Excel across Microsoft 365 Apps and the Office 2016, 2019, 2021, and 2024 releases, and confirm the fixed build numbers against Microsoft's advisory, since specific patched versions are not listed in the source data. Because exploitation requires user interaction, treating unsolicited spreadsheets as untrusted and relying on Protected View and email/web filtering limits interim risk. With no public PoC or known in-the-wild exploitation, patching on the normal update cycle is appropriate.
| microsoft Excel | — |
| Microsoft 365 | — |
| microsoft 365 Apps | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- 365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.