AI analysis
CVE-2026-81390 is an out-of-bounds read (CWE-125) in Microsoft Office Excel that allows an unauthenticated attacker to disclose information on a victim's local machine. The flaw is triggered when a user opens a specially crafted malicious file, causing Excel to read memory beyond the intended buffer and potentially expose sensitive process memory to the attacker. Impact is limited to confidentiality only (no code execution, integrity, or availability impact), consistent with the medium CVSS 3.1 score of 5.5 and local/user-interaction attack vector. A broad range of deployments are affected, including Microsoft 365 Apps, perpetual Office 2016, 2019, 2021, and 2024, and Office Online Server. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and EPSS assigns only a 0.4% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update for Office covering Excel across Microsoft 365 Apps and Office 2016/2019/2021/2024 via Microsoft Update or Click-to-Run auto-update, and patch Office Online Server manually since it does not auto-update. Enforce Protected View and 'block files originating from the internet' policies, and remind users not to open unexpected spreadsheet attachments, since the bug requires opening a crafted file. Note that Microsoft recently confirmed an Excel-related update (KB5002914) broke copy-and-paste functionality, so validate this patch in a pilot ring before broad deployment.
Affected
| Microsoft 365 Apps | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
| microsoft Excel | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
| Microsoft 365 | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
| microsoft Office 2016 | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
| microsoft Office 2019 | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
| microsoft Office 2021 | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
| microsoft Office 2024 | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
| microsoft Office Online Server | affected builds per Microsoft advisory (specific version ranges not enumerated in source data) |
Estimated exposure
masshundreds of millions of desktops worldwide (Microsoft 365 alone has roughly 400M+ commercial seats) — Excel ships with every supported Microsoft 365 Apps and perpetual Office installation, and Microsoft 365 commercial seats alone exceed 400 million, so essentially the global Office installed base across consumer, enterprise, and server…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.