Heap-Based Buffer Overflow in Microsoft Excel and Office Allows Local Code Execution
AI analysis
CVE-2026-81948 is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel that Microsoft addressed in its September 2026 Patch Tuesday release, allowing an unauthorized attacker to execute code locally. Given the local attack vector and user-interaction requirement (AV:L, UI:R), exploitation most likely requires a user to open a specially crafted spreadsheet in an affected version of Excel. A successful attack would run attacker-controlled code with the privileges of the signed-in user, with high impact on the confidentiality, integrity, and availability of the system. Users of Excel within Microsoft 365 / Microsoft 365 Apps and Office 2016, 2019, 2021, and 2024 are affected. As of this advisory there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for Excel and the affected Office 2016/2019/2021/2024 and Microsoft 365 Apps releases as soon as your patch cycle allows, and check Microsoft's advisory for the specific fixed build numbers (not included in the available data). Until patched, avoid opening spreadsheets from untrusted or unexpected sources, since user interaction with a crafted file is the most likely trigger. No emergency mitigation is indicated given the absence of known exploitation or public PoCs, but prioritize endpoints that routinely open externally supplied Excel files.
Affected
| Microsoft Excel (affected component across the listed Office releases) | — |
| Microsoft 365 | — |
| Microsoft 365 Apps (Office 365 Apps) | — |
| Microsoft Office 2016 | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
Estimated exposure
masshundreds of millions of users (Excel is present on a large share of Windows endpoints; Microsoft 365 alone is reported to have 400M+ paid seats) — Estimate based on the ubiquity of Excel across the Office/Microsoft 365 installed base (Microsoft 365 has hundreds of millions of paid seats and Office ships on most enterprise and consumer Windows PCs), noting that actual exploitability…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.