CVE-2026-81947
massHeap Buffer Overflow in Microsoft Excel Allows Local Code Execution
CVE-2026-81947 is a heap-based buffer overflow (CWE-122) in Microsoft Excel, the spreadsheet component of Microsoft Office. The CVSS vector (AV:L/AC:L/PR:N/UI:R) indicates exploitation occurs locally, requires no privileges, and depends on user interaction — consistent with a scenario in which a user is induced to open malicious Excel content. If exploited, an unauthorized attacker gains the ability to execute code on the victim's machine with that user's privileges, enabling data theft, malware installation, or a foothold for further compromise. Any user or deployment running Excel within Microsoft 365 Apps, Microsoft 365, Office 2016, 2019, 2021, or 2024, or Office Online Server is potentially affected. There is currently no known in-the-wild exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.3% chance of exploitation within the next 30 days.
What to do: Apply Microsoft's current security update for Excel/Office covering Microsoft 365 Apps, Office 2016/2019/2021/2024, and Office Online Server, prioritizing endpoints where users open files from external sources. Until patched, caution users about unsolicited or unexpected Excel files and rely on Protected View / Mark-of-the-Web handling, since exploitation requires user interaction. Administrators running Office Online Server should include those servers in the same update cycle and verify patch levels afterward.
| microsoft Excel | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
| microsoft Office Online Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- 365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024, office online server
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.