Heap Buffer Overflow in Microsoft Excel Allows Local Code Execution (CVE-2026-81959)
AI analysis
CVE-2026-81959 is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel, with an associated integer overflow/wraparound (CWE-190) that Microsoft notes as part of the flaw. Because the attack vector is local and requires user interaction, exploitation requires a user to open a specially crafted spreadsheet file in an affected Excel or Office installation, for example one delivered via email or downloaded from an untrusted source. Successful exploitation allows an unauthorized attacker to execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability on the victim machine. Anyone running Excel in Microsoft 365 Apps or perpetual Office 2016, 2019, 2021, or 2024 is affected. The flaw was addressed in Microsoft's September 2026 Patch Tuesday (a release covering 974 vulnerabilities); it is not in CISA KEV, no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at just 0.4%, so no confirmed in-the-wild exploitation is known.
What to do: Apply the September 2026 Patch Tuesday security updates for Microsoft Office/Excel across all affected channels (Microsoft 365 Apps and Office 2016/2019/2021/2024), then verify installed builds are at or above the September 2026 update level. Until patched, exercise caution with unsolicited spreadsheets, especially email attachments, since exploitation requires a user to open a malicious file.
Affected
| Microsoft Excel | — |
| Microsoft 365 Apps | — |
| Microsoft 365 (Office suite via subscription) | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Estimated exposure
masshundreds of millions of users/devices (Excel install base spanning Microsoft 365 and Office 2016 through 2024) — Excel ships with Microsoft 365, which Microsoft reports has hundreds of millions of commercial seats, plus large perpetual Office 2016-2024 installed bases, so the potential affected population is mass-scale, though only users who open…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.