ZeroHour

CVE-2026-81399

mass

Buffer Over-Read Information Disclosure in Microsoft Excel

CVSS 3.1
5.5 medium
EPSS
<1%p32
Published
()
Modified
AI analysis

CVE-2026-81399 is a buffer over-read (out-of-bounds read, CWE-126) in Microsoft Office Excel that allows an unauthorized attacker to disclose information locally. Exploitation requires user interaction: the victim must open a specially crafted spreadsheet, after which the flaw causes Excel to read past the intended buffer and potentially expose memory contents to the attacker. The impact is limited to confidentiality (CVSS 3.1: 5.5, medium) with no effect on integrity or availability, and the attack works only in the local context rather than over a network. All supported Office suites are in scope, including Microsoft 365 Apps, standalone Excel, and Office 2016, 2019, 2021, and 2024. No public proof of concept is known, the CVE is not on CISA's KEV list, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Deploy the relevant Microsoft security update for Excel across all supported Office versions (2016, 2019, 2021, 2024, and Microsoft 365 Apps) via Microsoft Update or Click-to-Run, since Microsoft 365 channel builds auto-update once patched. Because triggering requires a victim to open a malicious workbook, remind users not to open unsolicited spreadsheet attachments. Before broad rollout, note the vendor-confirmed known issue in which the KB5002914 update breaks copy and paste in Excel, and validate the workaround on a pilot group.

Affected
microsoft 365 apps
microsoft excel
microsoft 365
microsoft office 2016
microsoft office 2019
microsoft office 2021
microsoft office 2024
Estimated exposure
massHundreds of millions of desktops (Excel ships across Microsoft 365's 400M+ commercial seats plus consumer Office installs) — Excel is bundled with every Microsoft 365/Office subscription and perpetual Office release, and Microsoft reports over 400 million paid Microsoft 365 commercial seats, so the vulnerable install base plausibly exceeds one hundred million…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-126
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel

Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.

Microsoft added a known issue to KB5002914, the September 8, 2026 Excel security update, where paste, autofill, and formula dragging fail silently with no error in Excel 2016, 2019, 2021, and 2024. The update addresses remote code execution and information disclosure flaws including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. No hotfix date has been published as of September 15, 2026; the only widely confirmed recovery is uninstalling or rolling back KB5002914, which drops the month's Excel security fixes.