ZeroHour

CVE-2026-81954

mass

Use-After-Free Code Execution Flaw in Microsoft Excel (Office 2016-2024)

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-81954 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Office Excel, rated 7.8 (High) under CVSS 3.1, that allows an unauthorized attacker to execute code locally. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires no credentials or privileges but does require user interaction - in practice, getting a user to open a specially crafted spreadsheet file on a vulnerable Excel installation. If successful, the attacker's code runs in the context of the signed-in user, with high impact on confidentiality, integrity and availability of that machine (e.g., malware deployment, data theft, or a foothold for lateral movement on a corporate endpoint). Users of Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2016, 2019, 2021 and 2024 releases that include Excel are affected, per the listed CPE data. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-81954 via the Microsoft 365 Apps/Office update channel (or your WSUS/SCCM deployment pipeline) and verify installed Office builds against the affected and patched versions listed in Microsoft's advisory, which is the authoritative source for exact version ranges. Until patched, keep Office Protected View and Mark-of-the-Web enforcement enabled, treat unsolicited or unexpected spreadsheet attachments with caution, and monitor Microsoft's advisory for any update to exploitation status.

Affected
Microsoft Excel (affected component across listed Office SKUs)
Microsoft 365 Apps
Microsoft 365
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Microsoft 365 alone exceeds 400M paid commercial seats, plus the installed base of perpetual Office desktop releases) — Basis: Microsoft has publicly reported 400M+ paid Microsoft 365 seats and the Office desktop suite remains the default productivity software across enterprise and consumer fleets, so the installed base of the listed Excel-bearing releases…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel

Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.

Microsoft added a known issue to KB5002914, the September 8, 2026 Excel security update, where paste, autofill, and formula dragging fail silently with no error in Excel 2016, 2019, 2021, and 2024. The update addresses remote code execution and information disclosure flaws including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. No hotfix date has been published as of September 15, 2026; the only widely confirmed recovery is uninstalling or rolling back KB5002914, which drops the month's Excel security fixes.