ZeroHour

CVE-2026-81398

mass

Heap-Based Buffer Overflow in Microsoft Excel Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

Microsoft Excel contains a heap-based buffer overflow (CWE-122) that can be triggered by parsing maliciously crafted spreadsheet content. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires an unauthenticated attacker to lure a user into opening a hostile Excel file locally, with user interaction as the trigger. Successful exploitation yields arbitrary code execution in the context of the signed-in user, with high impact on confidentiality, integrity, and availability. The affected product set spans Excel within Microsoft 365/Microsoft 365 Apps and the perpetual Office 2016, 2019, 2021, and 2024 releases. Exploitation status is currently quiet: no in-the-wild reports, no known public PoC, not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-81398 from Microsoft's advisory to every affected Office channel in the environment, including Microsoft 365 Apps and supported perpetual Office releases, and verify the patched Excel build number against the advisory. Until patching completes, discourage opening spreadsheets from untrusted sources and rely on Protected View, email attachment filtering, and Office attack-surface-reduction rules to limit exposure. Note that the low EPSS and absence of a public PoC suggest limited near-term risk, but parser heap overflows in Office are a recurring exploitation target, so prioritize patching during the next maintenance cycle.

Affected
Microsoft Excel
Microsoft 365 Apps (includes Excel)
Microsoft 365
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of users/devices (Excel ships with Microsoft 365 and perpetual Office across consumer and enterprise desktops worldwide) — Excel is bundled with Microsoft 365 and the Office 2016-2024 perpetual releases, which together represent one of the largest desktop application installed bases globally, so the population of users who could open a malicious spreadsheet is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.