AI analysis
CVE-2026-81951 is a heap-based buffer overflow (CWE-122) in Microsoft Excel, the spreadsheet component of Microsoft Office and Microsoft 365. Per the CVSS vector (AV:L with UI:R and no privileges required), exploitation requires user interaction, most plausibly a user opening a crafted spreadsheet, rather than any network-reachable service. Successful exploitation lets an unauthorized attacker execute arbitrary code locally, with the CVSS scoring high impact on confidentiality, integrity, and availability. All supported Excel-bearing releases are affected: Microsoft 365 Apps/Microsoft 365, Office 2016, Office 2019, Office 2021, and Office 2024. No public proof of concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.4% chance of exploitation within 30 days, indicating no known in-the-wild exploitation as of the September 2026 Patch Tuesday that shipped the fix.
What to do: Apply Microsoft's September 2026 security updates for Microsoft 365 Apps and Office 2016/2019/2021/2024, then confirm endpoints are running the fixed build for their update channel. Until patched, treat unsolicited or untrusted spreadsheet files with caution, since exploitation requires a user to open a crafted workbook. With no public PoC or KEV listing and low EPSS, this can be handled within normal patch cycles, though endpoint fleets with heavy Excel use should expedite.
Affected
| Microsoft Excel | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| Microsoft Office 2016 | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
Estimated exposure
mass≈ hundreds of millions of Excel/Office installations worldwide — Microsoft 365 has hundreds of millions of paid seats and Office 2016-2024 remain widely deployed on-premises, and this flaw spans every supported Excel-bearing release in the CPE data.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.