ZeroHour

CVE-2026-81397

mass

Heap Buffer Overflow in Microsoft Excel Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-81397 is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel that can corrupt memory when the application processes crafted spreadsheet data. Triggering the flaw requires user interaction: an attacker must get a user to open a malicious workbook, after which the attacker can execute code with the permissions of that local user. Successful exploitation could expose files, alter data, or disrupt the affected workstation, since the CVSS impact ratings for confidentiality, integrity, and availability are all high. Anyone running Excel within Microsoft 365 / Microsoft 365 Apps or the perpetual Office 2016, 2019, 2021, and 2024 suites is potentially affected. As of now there is no evidence of exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Apply Microsoft's Excel/Office security update addressing CVE-2026-81397 across Microsoft Apps (all update channels) and the perpetual Office 2016, 2019, 2021, and 2024 update paths when it is published, and verify installed Office build numbers afterward against the advisory. Until patched, treat unsolicited or untrusted spreadsheets as suspect, since exploitation requires a user to open a crafted workbook locally. Given the lack of observed exploitation, no public PoC, and low EPSS (~0.4%), this can be handled in the regular patch cycle rather than as an emergency.

Affected
microsoft Excel (affected component within the listed suites)
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of installations (Excel ships in every Microsoft 365 and perpetual Office deployment) — Microsoft 365 and the perpetual Office suites are deployed across hundreds of millions of consumer and enterprise seats worldwide and Excel is included in all of them, so the potential installed base is on the order of 10^8, though only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.