Junglewise Threat Intelligence

CVE-2026-81389: Microsoft Office Excel heap-based buffer overflow

CVE-2026-81389 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Microsoft Office Excel is a spreadsheet application used by millions of organizations to manage financial data, reports, and business analytics. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer by crafting a malicious Excel file. If exploited, an attacker could gain full control of the affected system, access sensitive data, or distribute malware throughout an organization.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office Excel due to improper bounds checking when processing specially crafted Excel files. The vulnerability is triggered when a user opens a malicious .xlsx or related file format, causing memory corruption in the Excel process. An attacker can exploit this to execute arbitrary code with the privileges of the user running Excel, typically requiring user interaction (opening a file). While the vulnerability has been disclosed, no active exploitation in the wild has been reported at this time. A security patch is available from Microsoft.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats