AI analysis
CVE-2026-81949 is an integer overflow or wraparound (CWE-190) in Microsoft Office Excel that can corrupt memory when the application processes spreadsheet data. An attacker must deliver a specially crafted Excel file and persuade a user to open it, since the flaw is locally exploitable and requires user interaction with no special privileges. Successful exploitation allows the attacker to execute arbitrary code locally with the user's permissions, with high impact on confidentiality, integrity, and availability of the affected workstation. Users of Excel across Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2016, 2019, 2021, and 2024 releases are affected. There is no known in-the-wild exploitation, no public proof of concept, and Microsoft addressed the flaw in its September 2026 security updates.
What to do: Deploy the September 2026 Microsoft security updates for Office/Excel covering Microsoft 365 Apps and Office 2016/2019/2021/2024, and confirm endpoints are running a patched build. Until patched, caution users against opening Excel files from untrusted sources and prioritize hosts where users routinely open spreadsheet attachments. Note the EPSS probability of exploitation within 30 days is low (0.4%), but patching is still urgent given the local code-execution impact.
Affected
| microsoft Excel (Microsoft 365 Apps) | builds prior to the September 2026 security updates |
| microsoft Excel (Microsoft 365) | builds prior to the September 2026 security updates |
| microsoft Excel (Office 2016) | builds prior to the September 2026 security updates |
| microsoft Excel (Office 2019) | builds prior to the September 2026 security updates |
| microsoft Excel (Office 2021) | builds prior to the September 2026 security updates |
| microsoft Excel (Office 2024) | builds prior to the September 2026 security updates |
Estimated exposure
masshundreds of millions of users (Excel ships with every Microsoft 365 and perpetual Office install used across enterprises and consumers worldwide) — Excel is bundled with Microsoft 365 and the perpetual Office suites, giving it one of the largest desktop software footprints, so the plausible affected population is on the order of hundreds of millions of users; exact counts are unknown.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.