Junglewise Threat Intelligence

CVE-2026-81949: Microsoft Office Excel integer overflow allows local code execution

CVE-2026-81949 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Microsoft Office Excel is a widely used spreadsheet application in enterprise and personal computing. An integer overflow vulnerability in Excel allows an attacker with local access to execute arbitrary code with the privileges of the user running Excel, potentially compromising sensitive financial data, formulas, and other confidential spreadsheet information.

Technical details

An integer overflow or wraparound vulnerability exists in Microsoft Office Excel's internal processing logic. The vulnerability requires local access to the affected system and typically involves opening a specially crafted Excel file that triggers the integer overflow condition. When exploited, an attacker can bypass memory protections and execute arbitrary code with the same privileges as the user running Excel. The vulnerability is not known to be actively exploited in the wild. Microsoft has issued security patches to address this issue.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats