Junglewise Threat Intelligence

CVE-2026-81388: Microsoft Excel stack-based buffer overflow

CVE-2026-81388 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Microsoft Excel contains a stack-based buffer overflow vulnerability that allows an attacker with local access to execute arbitrary code on the affected system. A malicious Excel file crafted to trigger the overflow could enable an attacker to bypass security controls and gain full control of the system, threatening data confidentiality, integrity, and system availability.

Technical details

A stack-based buffer overflow exists in Microsoft Excel's file parsing logic, allowing an attacker to overwrite stack memory with arbitrary data. The vulnerability is triggered by processing a specially crafted Excel file, requiring local execution or user interaction (opening a file). Successful exploitation enables arbitrary code execution in the context of the user running Excel, potentially leading to system compromise. The attack vector is local, and while no active exploitation in the wild has been reported, the high CVSS score (7.8) reflects the severity of code execution capability.

Affected products

  • Microsoft Excel <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats