ZeroHour

CVE-2026-81396

mass

Stack-Based Buffer Overflow in Microsoft Excel Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-81396 is a stack-based buffer overflow (CWE-121, tagged alongside CWE-193 off-by-one) in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. The CVSS vector (AV:L/AC:L/PR:N/UI:R) indicates exploitation requires local access, no privileges, and user interaction, consistent with the typical Office scenario of a victim opening a maliciously crafted spreadsheet. Successful exploitation would let an attacker run arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity, and availability (scope unchanged). Anyone running Microsoft Excel — including Microsoft 365 Apps/Microsoft 365 and Office 2016, 2019, 2021, and 2024 — is potentially affected. As of now there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation within 30 days, so no active exploitation is known.

What to do: Install Microsoft's current security updates for Excel and the affected Office releases as soon as available, prioritizing endpoints where users open untrusted spreadsheets, and check Microsoft's advisory for the exact fixed builds. Until patched, discourage opening spreadsheets from untrusted sources and rely on Protected View / Mark-of-the-Web restrictions to reduce risk. Because EPSS is low and no PoC or in-the-wild exploitation is known, applying the patch on your normal cycle is reasonable except for high-risk users.

Affected
microsoft Excel
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of desktop installations/users worldwide (dominant Office/Microsoft 365 install base) — Excel ships with Microsoft 365 and the Office 2016–2024 suites, which run on hundreds of millions of enterprise and consumer endpoints, so essentially every Office deployment is exposed until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-121, CWE-193
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.