Junglewise Threat Intelligence

CVE-2026-81392: Microsoft Office Excel out-of-bounds read

CVE-2026-81392 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel contains an out-of-bounds read vulnerability that allows an attacker to read sensitive information from the system. An attacker would need local access to the computer to exploit this vulnerability. This could lead to unauthorized disclosure of confidential data stored in memory or on disk.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Excel where the application fails to properly validate memory access boundaries. The vulnerability allows an attacker with local access to craft a malicious Excel file that, when opened, triggers memory disclosure. This is a local-only attack requiring the victim to open a specially crafted spreadsheet file. The attacker can read sensitive information from adjacent memory regions, potentially exposing credentials, cached data, or other confidential information. A patch is expected from Microsoft's routine security updates.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats