ZeroHour

CVE-2026-81956

mass

Out-of-Bounds Read in Microsoft Excel Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-81956 is an out-of-bounds read (CWE-125) in the spreadsheet-parsing code of Microsoft Office Excel that Microsoft rates High (7.8). The flaw is triggered locally: an attacker must get a victim to open a specially crafted Excel file, since the attack vector is local with user interaction required and no special privileges needed. A successful exploit can allow an unauthorized attacker to execute code in the context of the local user, with high impact on confidentiality, integrity, and availability. Anyone running the affected Office builds is exposed, including Microsoft 365 Apps/Microsoft 365, Office 2016, 2019, 2021, and 2024, Excel itself, and Office Online Server. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV, with EPSS estimating only a 0.4% chance of exploitation within 30 days.

What to do: Apply the current Microsoft Office/Excel security updates from Microsoft's advisory (Patch Tuesday release) across all affected platforms, including Microsoft 365 Apps, the perpetual Office 2016/2019/2021/2024 editions, and any Office Online Server farms. Until patched, treat unsolicited or untrusted .xlsx/.xls files with caution since exploitation requires a user to open a crafted spreadsheet. Inventory Excel and Office Online Server deployments and prioritize end-user workstations and file-preview/rendering servers for patching.

Affected
Microsoft Excel
Microsoft 365 Apps
Microsoft 365
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Microsoft Office Online Server
Estimated exposure
masshundreds of millions of users (Office/Excel is deployed on well over a billion devices; Microsoft 365 has 400M+ paid seats) — Excel ships with every Microsoft 365 and perpetual Office license and is near-universal on Windows and Mac desktops in enterprise and consumer environments, so essentially the entire Office install base is plausibly affected until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024, office online server
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.