CVE-2026-81960
massHeap Buffer Overflow in Microsoft Excel Allows Local Code Execution
CVE-2026-81960 is a heap-based buffer overflow (CWE-122) in the spreadsheet component of Microsoft Excel that can corrupt memory when the application processes crafted content. The CVSS vector (AV:L/PR:N/UI:R) indicates exploitation requires user interaction in a local context, most plausibly a user opening a malicious spreadsheet, with no special privileges needed beforehand. A successful attack lets an unauthorized attacker execute arbitrary code locally with the privileges of the logged-in user, with high impact on confidentiality, integrity, and availability of the endpoint. Per Microsoft's CPE data, affected deployments include Microsoft 365 and Microsoft 365 Apps as well as perpetual Office 2016, 2019, 2021, and 2024. There is currently no public proof-of-concept, no CISA KEV listing, and a low 0.4% EPSS score, indicating no known exploitation in the wild.
What to do: Apply the Microsoft security update for Excel covering Microsoft 365 Apps and Office 2016/2019/2021/2024 as soon as it is published, prioritizing shared and privileged workstations, and verify installed Office build numbers against Microsoft's advisory since this data does not include exact version ranges. Because exploitation requires user interaction (opening crafted content), caution users about unsolicited spreadsheets and keep Office Protected View and macro/security warnings enabled.
| Microsoft Excel | — |
| Microsoft 365 | — |
| Microsoft 365 Apps | — |
| Microsoft Office 2016 | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- 365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.