Junglewise Threat Intelligence

CVE-2026-81395: Microsoft Office Excel out-of-bounds read

CVE-2026-81395 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel contains an out-of-bounds memory read vulnerability that allows an attacker to access and disclose sensitive information stored in memory. The vulnerability requires local access to the system and could enable an attacker to read confidential data such as passwords, encryption keys, or other sensitive content from affected user systems.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Excel's memory handling routines. The vulnerability occurs when Excel attempts to read data beyond the allocated bounds of a memory buffer, potentially exposing adjacent memory contents to an attacker. This is a local attack that requires the attacker to execute code or interact with a malicious file on the target system. Successful exploitation allows disclosure of sensitive information stored in the process memory of Excel.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats