CVE-2026-81396
massStack-Based Buffer Overflow in Microsoft Excel Enables Local Code Execution
CVE-2026-81396 is a stack-based buffer overflow (CWE-121, tagged alongside CWE-193 off-by-one) in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. The CVSS vector (AV:L/AC:L/PR:N/UI:R) indicates exploitation requires local access, no privileges, and user interaction, consistent with the typical Office scenario of a victim opening a maliciously crafted spreadsheet. Successful exploitation would let an attacker run arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity, and availability (scope unchanged). Anyone running Microsoft Excel — including Microsoft 365 Apps/Microsoft 365 and Office 2016, 2019, 2021, and 2024 — is potentially affected. As of now there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation within 30 days, so no active exploitation is known.
What to do: Install Microsoft's current security updates for Excel and the affected Office releases as soon as available, prioritizing endpoints where users open untrusted spreadsheets, and check Microsoft's advisory for the exact fixed builds. Until patched, discourage opening spreadsheets from untrusted sources and rely on Protected View / Mark-of-the-Web restrictions to reduce risk. Because EPSS is low and no PoC or in-the-wild exploitation is known, applying the patch on your normal cycle is reasonable except for high-risk users.
| microsoft Excel | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- 365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-121, CWE-193
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.