AI analysis
CVE-2026-81950 is a double-free memory-corruption flaw (CWE-415) in Microsoft Excel, the spreadsheet component of Microsoft Office. Based on the CVSS vector (local attack vector, no privileges, user interaction required), it is triggered by convincing a user to open a specially crafted spreadsheet or otherwise process attacker-controlled data in an affected Excel build. A successful exploit lets an unauthorized attacker execute arbitrary code in the context of the local user, with high impact to confidentiality, integrity, and availability. Users of Excel in Microsoft 365 Apps/Microsoft 365 and the perpetual Office 2016, 2019, 2021, and 2024 releases are affected. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.4%), indicating no confirmed exploitation; the flaw was addressed in Microsoft's September 2026 security updates.
What to do: Apply the September 2026 Microsoft security updates for Office/Excel across all affected releases (Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps) and confirm the updated Excel build numbers in Microsoft's advisory. Until patching is complete, instruct users not to open spreadsheet attachments or files from untrusted sources, since exploitation requires user interaction with a malicious file. Monitor Microsoft advisories for revised build numbers and consider standard Office hardening (e.g., Protected View) as interim mitigation.
Affected
| Microsoft Excel (Microsoft 365 Apps / Microsoft 365) | affected builds as identified by Microsoft; addressed by the September 2026 security updates |
| Microsoft Excel (standalone), Office 2016 | affected builds as identified by Microsoft; addressed by the September 2026 security updates |
| Microsoft Excel, Office 2019 | affected builds as identified by Microsoft; addressed by the September 2026 security updates |
| Microsoft Excel, Office 2021 | affected builds as identified by Microsoft; addressed by the September 2026 security updates |
| Microsoft Excel, Office 2024 | affected builds as identified by Microsoft; addressed by the September 2026 security updates |
Estimated exposure
masson the order of 1 billion+ users (Office/Excel is the dominant desktop productivity suite, and all supported Office 2016-2024 and Microsoft 365 channels are… — Microsoft Office is installed on well over a billion devices worldwide and the affected CPEs span every currently supported Office release channel, so essentially the entire installed base of supported Excel versions is plausibly exposed.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.