ZeroHour

CVE-2026-81386

mass

Heap Buffer Overflow in Microsoft Excel Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-81386 is a heap-based buffer overflow (CWE-122) in the Excel component of Microsoft Office. The CVSS vector indicates a local attack vector with user interaction required, meaning an attacker must get a local user to trigger the flaw, consistent with opening specially crafted spreadsheet content that corrupts Excel's heap memory. Successful exploitation lets the unauthorized attacker execute code in the context of the local user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). Anyone running Excel within Microsoft 365 Apps or the Office 2016, 2019, 2021, and 2024 releases is potentially affected. There is no evidence of active exploitation: no public proof of concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (29th percentile).

What to do: Apply Microsoft's current security updates for Excel across Microsoft 365 Apps and the Office 2016, 2019, 2021, and 2024 releases, and confirm the fixed build numbers against Microsoft's advisory, since specific patched versions are not listed in the source data. Because exploitation requires user interaction, treating unsolicited spreadsheets as untrusted and relying on Protected View and email/web filtering limits interim risk. With no public PoC or known in-the-wild exploitation, patching on the normal update cycle is appropriate.

Affected
microsoft Excel
Microsoft 365
microsoft 365 Apps
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Excel ships in every Microsoft 365 Apps and Office 2016-2024 install) — Excel is included in all affected Office and Microsoft 365 Apps deployments, which together have hundreds of millions of commercial seats and consumer installations worldwide, so the potentially affected base is on the order of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.