AI analysis
Microsoft has fixed a stack-based buffer overflow (CWE-121) in Microsoft Office Excel that allows an unauthorized local attacker to execute arbitrary code. Given the CVSS vector (local attack vector, no privileges required, user interaction required), exploitation most plausibly requires a user to open a specially crafted spreadsheet, for example delivered via email or a shared location. Successful exploitation yields code execution in the context of the user who opened the file, with high impact on confidentiality, integrity and availability. Anyone running Excel — including Microsoft 365/365 Apps and the perpetual Office 2016, 2019, 2021 and 2024 releases — is affected, and the fix shipped in the September 2026 Microsoft Patch Tuesday release. There is no known public proof of concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's September 2026 security updates to Microsoft 365/365 Apps and Office 2016/2019/2021/2024, checking Microsoft's advisory for the exact KB/build for each version. Until patched, treat unsolicited or untrusted Excel attachments as suspect since exploitation requires a user to open a crafted file. The issue is not known to be exploited (no public PoC, not in CISA KEV, EPSS 0.4%), so a routine patching cycle is likely sufficient, prioritizing mail-heavy and shared-workstation users.
Affected
| microsoft Excel | — |
| Microsoft 365 | affected builds as addressed in Microsoft's September 2026 security update |
| microsoft 365 Apps | affected builds as addressed in Microsoft's September 2026 security update |
| microsoft Office 2016 | affected builds as addressed in Microsoft's September 2026 security update |
| microsoft Office 2019 | affected builds as addressed in Microsoft's September 2026 security update |
| microsoft Office 2021 | affected builds as addressed in Microsoft's September 2026 security update |
| microsoft Office 2024 | affected builds as addressed in Microsoft's September 2026 security update |
Estimated exposure
mass≈ hundreds of millions of users (Excel ships as a core component of Office/Microsoft 365, whose installed base spans hundreds of millions of seats) — Excel is bundled with Microsoft 365 and perpetual Office releases deployed across hundreds of millions of commercial and consumer seats, so effectively every managed Office environment is within scope of this flaw.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.