Junglewise Threat Intelligence

CVE-2026-81390: Microsoft Office Excel out-of-bounds read

CVE-2026-81390 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel is a spreadsheet application widely used across enterprises for data analysis and reporting. A flaw in the application allows an attacker with local access to read sensitive data from Excel's memory, potentially exposing confidential information contained in spreadsheets or the application's internal state.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Excel where the application fails to properly validate memory access boundaries. The vulnerability can be exploited by a local attacker to read beyond allocated memory regions, disclosing sensitive information from the Excel process. This is a memory safety issue that does not require network access or authentication, but does require local system access. The attacker gains information disclosure capability without achieving code execution.

Affected products

  • Microsoft Office Excel <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats