ZeroHour

CVE-2026-85875

mass

Out-of-Bounds Read in Microsoft Excel Leads to Local Information Disclosure

CVSS 3.1
5.5 medium
EPSS
<1%p31
Published
()
Modified
AI analysis

CVE-2026-85875 is an out-of-bounds read (CWE-125) in Microsoft Excel, the spreadsheet component of Microsoft Office, rated 5.5 (Medium) on the CVSS 3.1 scale. Exploitation is local and requires user interaction: an unauthenticated attacker must persuade a user to open a specially crafted workbook, causing Excel to read past the end of an allocated memory buffer. A successful attack discloses sensitive information from process memory (high confidentiality impact), with no impact on integrity or availability. Affected products include Excel within Microsoft 365 Apps and Microsoft 365, as well as the perpetual Office 2016, 2019, 2021, and 2024 releases. Exploitation status is none known: the flaw is not in CISA KEV, no public proof-of-concept has been published, EPSS is low at 0.4%, and it was addressed in Microsoft's September 2026 Patch Tuesday release (973-974 fixes, including 2 exploited zero-days not attributed to this CVE).

What to do: Apply the September 2026 Microsoft security updates for Excel/Office across all affected editions (Microsoft 365 Apps and Office 2016, 2019, 2021, 2024), using your normal Office update channel or WSUS/Intune reporting to confirm deployment. Because the flaw requires a local user to open a crafted workbook, reinforce user caution around spreadsheets from untrusted sources until patching completes. No public exploit exists and EPSS is low, so there is no urgent emergency-patching driver, but close this out in your regular Patch Tuesday cycle.

Affected
microsoft Excel (Microsoft Office Excel)
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions to 1 billion+ Office/Excel users worldwide — Excel ships with every copy of Microsoft Office and Microsoft 365, whose combined installed base is commonly cited at over a billion users with hundreds of millions of commercial seats, though actual exploitation risk is limited to local,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs