Impact
Microsoft Office Excel contains a heap‑based buffer overflow that enables an unauthorized attacker with access to the victim’s machine to execute arbitrary code locally. The flaw arises when Excel processes certain data structures without proper bounds checking, giving the attacker the ability to overwrite memory and control program flow. Successful exploitation could compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
All Microsoft Office products listed by the CNA are impacted. This includes Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version details were not provided, so all versions of these products are potentially vulnerable until patches are applied.
Risk and Exploitability
CVE-2026-81386 has a CVSS score of 7.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV. The attack vector is most likely local, requiring an unauthorized user to deliver an exploit payload via an Excel file or untrusted data input. If an attacker can persuade a user to open a crafted workbook or otherwise trigger the vulnerable code path, arbitrary code execution can be achieved. The lack of a remote execution entry point limits exploitation to scenarios where the attacker can influence the victim’s file system or application context.
OpenCVE Enrichment