Junglewise Threat Intelligence

CVE-2026-81954: Microsoft Office Excel use after free memory corruption

CVE-2026-81954 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Microsoft Office Excel is a widely used spreadsheet application for business data analysis and reporting. A use-after-free vulnerability in Excel could allow an attacker to execute arbitrary code on a victim's computer through a maliciously crafted spreadsheet file, potentially leading to unauthorized access, data theft, or system compromise.

Technical details

This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Excel. The flaw allows an attacker to execute arbitrary code with local privileges by crafting a malicious Excel file. The attack vector is local—requiring user interaction (opening a malicious file)—but no prior authentication is required. If exploited, an attacker could achieve code execution in the context of the user running Excel, with potential for data exfiltration or lateral movement within an organization.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats