ZeroHour

CVE-2026-81953

mass

Stack-Based Buffer Overflow in Microsoft Excel Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

Microsoft has fixed a stack-based buffer overflow (CWE-121) in Microsoft Office Excel that allows an unauthorized local attacker to execute arbitrary code. Given the CVSS vector (local attack vector, no privileges required, user interaction required), exploitation most plausibly requires a user to open a specially crafted spreadsheet, for example delivered via email or a shared location. Successful exploitation yields code execution in the context of the user who opened the file, with high impact on confidentiality, integrity and availability. Anyone running Excel — including Microsoft 365/365 Apps and the perpetual Office 2016, 2019, 2021 and 2024 releases — is affected, and the fix shipped in the September 2026 Microsoft Patch Tuesday release. There is no known public proof of concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's September 2026 security updates to Microsoft 365/365 Apps and Office 2016/2019/2021/2024, checking Microsoft's advisory for the exact KB/build for each version. Until patched, treat unsolicited or untrusted Excel attachments as suspect since exploitation requires a user to open a crafted file. The issue is not known to be exploited (no public PoC, not in CISA KEV, EPSS 0.4%), so a routine patching cycle is likely sufficient, prioritizing mail-heavy and shared-workstation users.

Affected
microsoft Excel
Microsoft 365affected builds as addressed in Microsoft's September 2026 security update
microsoft 365 Appsaffected builds as addressed in Microsoft's September 2026 security update
microsoft Office 2016affected builds as addressed in Microsoft's September 2026 security update
microsoft Office 2019affected builds as addressed in Microsoft's September 2026 security update
microsoft Office 2021affected builds as addressed in Microsoft's September 2026 security update
microsoft Office 2024affected builds as addressed in Microsoft's September 2026 security update
Estimated exposure
mass≈ hundreds of millions of users (Excel ships as a core component of Office/Microsoft 365, whose installed base spans hundreds of millions of seats) — Excel is bundled with Microsoft 365 and perpetual Office releases deployed across hundreds of millions of commercial and consumer seats, so effectively every managed Office environment is within scope of this flaw.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.