ZeroHour

CVE-2026-81950

mass

Double-Free Vulnerability in Microsoft Excel Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-81950 is a double-free memory-corruption flaw (CWE-415) in Microsoft Excel, the spreadsheet component of Microsoft Office. Based on the CVSS vector (local attack vector, no privileges, user interaction required), it is triggered by convincing a user to open a specially crafted spreadsheet or otherwise process attacker-controlled data in an affected Excel build. A successful exploit lets an unauthorized attacker execute arbitrary code in the context of the local user, with high impact to confidentiality, integrity, and availability. Users of Excel in Microsoft 365 Apps/Microsoft 365 and the perpetual Office 2016, 2019, 2021, and 2024 releases are affected. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.4%), indicating no confirmed exploitation; the flaw was addressed in Microsoft's September 2026 security updates.

What to do: Apply the September 2026 Microsoft security updates for Office/Excel across all affected releases (Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps) and confirm the updated Excel build numbers in Microsoft's advisory. Until patching is complete, instruct users not to open spreadsheet attachments or files from untrusted sources, since exploitation requires user interaction with a malicious file. Monitor Microsoft advisories for revised build numbers and consider standard Office hardening (e.g., Protected View) as interim mitigation.

Affected
Microsoft Excel (Microsoft 365 Apps / Microsoft 365)affected builds as identified by Microsoft; addressed by the September 2026 security updates
Microsoft Excel (standalone), Office 2016affected builds as identified by Microsoft; addressed by the September 2026 security updates
Microsoft Excel, Office 2019affected builds as identified by Microsoft; addressed by the September 2026 security updates
Microsoft Excel, Office 2021affected builds as identified by Microsoft; addressed by the September 2026 security updates
Microsoft Excel, Office 2024affected builds as identified by Microsoft; addressed by the September 2026 security updates
Estimated exposure
masson the order of 1 billion+ users (Office/Excel is the dominant desktop productivity suite, and all supported Office 2016-2024 and Microsoft 365 channels are… — Microsoft Office is installed on well over a billion devices worldwide and the affected CPEs span every currently supported Office release channel, so essentially the entire installed base of supported Excel versions is plausibly exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.