CVE-2026-81397
massHeap Buffer Overflow in Microsoft Excel Allows Local Code Execution
CVE-2026-81397 is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel that can corrupt memory when the application processes crafted spreadsheet data. Triggering the flaw requires user interaction: an attacker must get a user to open a malicious workbook, after which the attacker can execute code with the permissions of that local user. Successful exploitation could expose files, alter data, or disrupt the affected workstation, since the CVSS impact ratings for confidentiality, integrity, and availability are all high. Anyone running Excel within Microsoft 365 / Microsoft 365 Apps or the perpetual Office 2016, 2019, 2021, and 2024 suites is potentially affected. As of now there is no evidence of exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Apply Microsoft's Excel/Office security update addressing CVE-2026-81397 across Microsoft Apps (all update channels) and the perpetual Office 2016, 2019, 2021, and 2024 update paths when it is published, and verify installed Office build numbers afterward against the advisory. Until patched, treat unsolicited or untrusted spreadsheets as suspect, since exploitation requires a user to open a crafted workbook locally. Given the lack of observed exploitation, no public PoC, and low EPSS (~0.4%), this can be handled in the regular patch cycle rather than as an emergency.
| microsoft Excel (affected component within the listed suites) | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- 365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.