ZeroHour

CVE-2026-81957

mass

Out-of-bounds read in Microsoft Excel allows local code execution

CVSS 3.1
7.8 high
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-81957 is an out-of-bounds read (CWE-125) in the Excel component of Microsoft Office that Microsoft, as the assigning CNA, rates as allowing an unauthorized attacker to execute code locally. The CVSS vector (AV:L/AC:L/PR:N/UI:R) indicates the flaw is exploited locally, requires no special privileges, and needs user interaction, which in practice means a user opening a maliciously crafted spreadsheet on their machine. Successful exploitation would let the attacker run code in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, high). Affected products include the Excel component of Microsoft 365 Apps and Microsoft 365, as well as the perpetual Office 2016, 2019, 2021, and 2024 releases; exact affected and fixed version ranges are not specified in the available data. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at roughly 0.4% (36th percentile).

What to do: Apply Microsoft's security update addressing CVE-2026-81957 for Excel as soon as it is available, via the Microsoft 365 Apps update channel or Office updates for Office 2016/2019/2021/2024, and verify installed Excel builds against the fixed versions listed in the Microsoft advisory. Until patched, discourage opening spreadsheets from untrusted sources, since exploitation requires user interaction with a crafted file. Given the absence of known exploitation, a public PoC, and low EPSS, this can be handled on a normal patch cycle rather than as an emergency.

Affected
microsoft Excel (component of Office and Microsoft 365 Apps)
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users/desktops running Excel across Microsoft 365 and perpetual Office installs — Microsoft 365 alone has hundreds of millions of commercial seats and perpetual Office/Excel remains ubiquitous on managed Windows desktops, so the potential exposed installed base is in the hundreds of millions of users, though the number…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.