ZeroHour

CVE-2026-81390

mass

Out-of-Bounds Read in Microsoft Excel Enables Local Information Disclosure

CVSS 3.1
5.5 medium
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-81390 is an out-of-bounds read (CWE-125) in Microsoft Office Excel that allows an unauthenticated attacker to disclose information on a victim's local machine. The flaw is triggered when a user opens a specially crafted malicious file, causing Excel to read memory beyond the intended buffer and potentially expose sensitive process memory to the attacker. Impact is limited to confidentiality only (no code execution, integrity, or availability impact), consistent with the medium CVSS 3.1 score of 5.5 and local/user-interaction attack vector. A broad range of deployments are affected, including Microsoft 365 Apps, perpetual Office 2016, 2019, 2021, and 2024, and Office Online Server. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and EPSS assigns only a 0.4% probability of exploitation within 30 days.

What to do: Apply the Microsoft security update for Office covering Excel across Microsoft 365 Apps and Office 2016/2019/2021/2024 via Microsoft Update or Click-to-Run auto-update, and patch Office Online Server manually since it does not auto-update. Enforce Protected View and 'block files originating from the internet' policies, and remind users not to open unexpected spreadsheet attachments, since the bug requires opening a crafted file. Note that Microsoft recently confirmed an Excel-related update (KB5002914) broke copy-and-paste functionality, so validate this patch in a pilot ring before broad deployment.

Affected
Microsoft 365 Appsaffected builds per Microsoft advisory (specific version ranges not enumerated in source data)
microsoft Excelaffected builds per Microsoft advisory (specific version ranges not enumerated in source data)
Microsoft 365affected builds per Microsoft advisory (specific version ranges not enumerated in source data)
microsoft Office 2016affected builds per Microsoft advisory (specific version ranges not enumerated in source data)
microsoft Office 2019affected builds per Microsoft advisory (specific version ranges not enumerated in source data)
microsoft Office 2021affected builds per Microsoft advisory (specific version ranges not enumerated in source data)
microsoft Office 2024affected builds per Microsoft advisory (specific version ranges not enumerated in source data)
microsoft Office Online Serveraffected builds per Microsoft advisory (specific version ranges not enumerated in source data)
Estimated exposure
masshundreds of millions of desktops worldwide (Microsoft 365 alone has roughly 400M+ commercial seats) — Excel ships with every supported Microsoft 365 Apps and perpetual Office installation, and Microsoft 365 commercial seats alone exceed 400 million, so essentially the global Office installed base across consumer, enterprise, and server…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024, office online server
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel

Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.

Microsoft added a known issue to KB5002914, the September 8, 2026 Excel security update, where paste, autofill, and formula dragging fail silently with no error in Excel 2016, 2019, 2021, and 2024. The update addresses remote code execution and information disclosure flaws including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. No hotfix date has been published as of September 15, 2026; the only widely confirmed recovery is uninstalling or rolling back KB5002914, which drops the month's Excel security fixes.