ZeroHour

CVE-2026-81949

mass

Integer Overflow in Microsoft Excel Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-81949 is an integer overflow or wraparound (CWE-190) in Microsoft Office Excel that can corrupt memory when the application processes spreadsheet data. An attacker must deliver a specially crafted Excel file and persuade a user to open it, since the flaw is locally exploitable and requires user interaction with no special privileges. Successful exploitation allows the attacker to execute arbitrary code locally with the user's permissions, with high impact on confidentiality, integrity, and availability of the affected workstation. Users of Excel across Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2016, 2019, 2021, and 2024 releases are affected. There is no known in-the-wild exploitation, no public proof of concept, and Microsoft addressed the flaw in its September 2026 security updates.

What to do: Deploy the September 2026 Microsoft security updates for Office/Excel covering Microsoft 365 Apps and Office 2016/2019/2021/2024, and confirm endpoints are running a patched build. Until patched, caution users against opening Excel files from untrusted sources and prioritize hosts where users routinely open spreadsheet attachments. Note the EPSS probability of exploitation within 30 days is low (0.4%), but patching is still urgent given the local code-execution impact.

Affected
microsoft Excel (Microsoft 365 Apps)builds prior to the September 2026 security updates
microsoft Excel (Microsoft 365)builds prior to the September 2026 security updates
microsoft Excel (Office 2016)builds prior to the September 2026 security updates
microsoft Excel (Office 2019)builds prior to the September 2026 security updates
microsoft Excel (Office 2021)builds prior to the September 2026 security updates
microsoft Excel (Office 2024)builds prior to the September 2026 security updates
Estimated exposure
masshundreds of millions of users (Excel ships with every Microsoft 365 and perpetual Office install used across enterprises and consumers worldwide) — Excel is bundled with Microsoft 365 and the perpetual Office suites, giving it one of the largest desktop software footprints, so the plausible affected population is on the order of hundreds of millions of users; exact counts are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.