Junglewise Threat Intelligence

CVE-2026-81960: Microsoft Office Excel heap buffer overflow

CVE-2026-81960 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Microsoft Office Excel is a widely used spreadsheet application in corporate environments. This vulnerability allows a local attacker with file access to execute arbitrary code on a user's computer by crafting a malicious Excel file, potentially leading to data theft, malware installation, or system compromise.

Technical details

A heap-based buffer overflow exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when processing specially crafted Excel files and allows an attacker to overwrite heap memory and achieve code execution. The attack requires local access and user interaction (opening a malicious file). No network vector is available. Patches are expected from Microsoft's security updates.

Affected products

  • Microsoft Office Excel <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats