Junglewise Threat Intelligence

CVE-2026-81399: Microsoft Office Excel buffer over-read information disclosure

CVE-2026-81399 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel contains a buffer over-read vulnerability that allows a local attacker to read sensitive information from the application's memory. An attacker with local access to a system could exploit this flaw to extract confidential data such as passwords, encryption keys, or other sensitive information stored in memory during Excel operation.

Technical details

The vulnerability is a buffer over-read flaw in Microsoft Office Excel that allows an unauthorized attacker to disclose information through local access. The buffer over-read permits reading beyond allocated memory boundaries, potentially exposing sensitive data stored in adjacent memory regions. Attack requires local access to the system and the ability to trigger the vulnerable code path in Excel. An attacker can leverage this to extract confidential information from the process memory. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office Excel <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats