ZeroHour

CVE-2026-81948

mass

Heap-Based Buffer Overflow in Microsoft Excel and Office Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-81948 is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel that Microsoft addressed in its September 2026 Patch Tuesday release, allowing an unauthorized attacker to execute code locally. Given the local attack vector and user-interaction requirement (AV:L, UI:R), exploitation most likely requires a user to open a specially crafted spreadsheet in an affected version of Excel. A successful attack would run attacker-controlled code with the privileges of the signed-in user, with high impact on the confidentiality, integrity, and availability of the system. Users of Excel within Microsoft 365 / Microsoft 365 Apps and Office 2016, 2019, 2021, and 2024 are affected. As of this advisory there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for Excel and the affected Office 2016/2019/2021/2024 and Microsoft 365 Apps releases as soon as your patch cycle allows, and check Microsoft's advisory for the specific fixed build numbers (not included in the available data). Until patched, avoid opening spreadsheets from untrusted or unexpected sources, since user interaction with a crafted file is the most likely trigger. No emergency mitigation is indicated given the absence of known exploitation or public PoCs, but prioritize endpoints that routinely open externally supplied Excel files.

Affected
Microsoft Excel (affected component across the listed Office releases)
Microsoft 365
Microsoft 365 Apps (Office 365 Apps)
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Excel is present on a large share of Windows endpoints; Microsoft 365 alone is reported to have 400M+ paid seats) — Estimate based on the ubiquity of Excel across the Office/Microsoft 365 installed base (Microsoft 365 has hundreds of millions of paid seats and Office ships on most enterprise and consumer Windows PCs), noting that actual exploitability…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.