ZeroHour

CVE-2026-81960

mass

Heap Buffer Overflow in Microsoft Excel Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-81960 is a heap-based buffer overflow (CWE-122) in the spreadsheet component of Microsoft Excel that can corrupt memory when the application processes crafted content. The CVSS vector (AV:L/PR:N/UI:R) indicates exploitation requires user interaction in a local context, most plausibly a user opening a malicious spreadsheet, with no special privileges needed beforehand. A successful attack lets an unauthorized attacker execute arbitrary code locally with the privileges of the logged-in user, with high impact on confidentiality, integrity, and availability of the endpoint. Per Microsoft's CPE data, affected deployments include Microsoft 365 and Microsoft 365 Apps as well as perpetual Office 2016, 2019, 2021, and 2024. There is currently no public proof-of-concept, no CISA KEV listing, and a low 0.4% EPSS score, indicating no known exploitation in the wild.

What to do: Apply the Microsoft security update for Excel covering Microsoft 365 Apps and Office 2016/2019/2021/2024 as soon as it is published, prioritizing shared and privileged workstations, and verify installed Office build numbers against Microsoft's advisory since this data does not include exact version ranges. Because exploitation requires user interaction (opening crafted content), caution users about unsolicited spreadsheets and keep Office Protected View and macro/security warnings enabled.

Affected
Microsoft Excel
Microsoft 365
Microsoft 365 Apps
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Excel is bundled with Microsoft 365 and perpetual Office editions on the large majority of Windows and Mac desktops) — Excel ships with Microsoft 365 (reported at 400M+ paid seats) and the Office 2016-2024 perpetual suites installed across most corporate and consumer endpoints, so the affected population is plausibly in the hundreds of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.