CVE-2026-81956
massOut-of-Bounds Read in Microsoft Excel Allows Local Code Execution
CVE-2026-81956 is an out-of-bounds read (CWE-125) in the spreadsheet-parsing code of Microsoft Office Excel that Microsoft rates High (7.8). The flaw is triggered locally: an attacker must get a victim to open a specially crafted Excel file, since the attack vector is local with user interaction required and no special privileges needed. A successful exploit can allow an unauthorized attacker to execute code in the context of the local user, with high impact on confidentiality, integrity, and availability. Anyone running the affected Office builds is exposed, including Microsoft 365 Apps/Microsoft 365, Office 2016, 2019, 2021, and 2024, Excel itself, and Office Online Server. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV, with EPSS estimating only a 0.4% chance of exploitation within 30 days.
What to do: Apply the current Microsoft Office/Excel security updates from Microsoft's advisory (Patch Tuesday release) across all affected platforms, including Microsoft 365 Apps, the perpetual Office 2016/2019/2021/2024 editions, and any Office Online Server farms. Until patched, treat unsolicited or untrusted .xlsx/.xls files with caution since exploitation requires a user to open a crafted spreadsheet. Inventory Excel and Office Online Server deployments and prioritize end-user workstations and file-preview/rendering servers for patching.
| Microsoft Excel | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| Microsoft Office 2016 | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
| Microsoft Office Online Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- 365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024, office online server
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.