Junglewise Threat Intelligence

CVE-2026-81387: Microsoft Office Excel local information disclosure

CVE-2026-81387 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel is a widely-used spreadsheet application in corporate environments. This vulnerability allows an attacker with local access to the system to read sensitive information that should not be accessible, potentially exposing confidential business data or system configuration details.

Technical details

This vulnerability is an information disclosure flaw in Microsoft Office Excel that exposes sensitive system information to an unauthorized control sphere. The attack requires local access to the affected system. An attacker can exploit this to read sensitive data that should be protected. The vulnerability has a CVSS score of 5.5 (medium severity) and has not been reported as exploited in the wild as of the advisory publication date.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats