Description
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An out-of-bounds read flaw in Microsoft Office Excel permits an unauthorized user to execute code on the local system. The vulnerability originates from improper bounds checking when processing Excel files, which can lead to arbitrary code execution if the file is opened or processed by a user who has ability to place the file in a location that will be read by the software. The impact is the loss of confidentiality, integrity and availability of the affected system, as malware could run with the privileges of the logged‑in user. The weak point is classified under CWE-125, an out-of-bounds read.

Affected Systems

The flaw affects multiple Microsoft Office product families including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. All versions listed in the CNA product list are susceptible.

Risk and Exploitability

The CVSS score of 7.8 indicates a high level of severity. EPSS is not available, so the likelihood of exploitation cannot be quantified from the current data. The vulnerability is not listed in the CISA KEV catalog. Because the problem requires the victim to open a malicious file locally, the attack vector is inferred to be local and relies on user interaction or the presence of a file in a directory accessed by the application. A bypass of the normal bounds verification would allow execution of arbitrary local code with the privileges of the user.

Generated by OpenCVE AI on September 9, 2026 at 20:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office security update that addresses CVE-2026-81956 as published in the Microsoft Security Update Guide.
  • Configure Office to disable or restrict macro execution, ensuring that only signed or approved macros run.
  • Configure Office to open documents in Protected View mode unless the user explicitly chooses to enable editing, reducing the risk of executing code from untrusted documents.

Generated by OpenCVE AI on September 9, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Excel 2016
Microsoft microsoft Office 2016
Microsoft microsoft Office 2019
Microsoft microsoft Office 365 For Mac
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024
Vendors & Products Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Excel 2016
Microsoft microsoft Office 2016
Microsoft microsoft Office 2019
Microsoft microsoft Office 365 For Mac
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024

Wed, 09 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft excel
Microsoft microsoft 365
Microsoft office Online Server
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:*
Vendors & Products Microsoft excel
Microsoft microsoft 365
Microsoft office Online Server

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Title Microsoft Excel Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft excel 2016
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:excel_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:ltsc:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft excel 2016
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Excel Excel 2016 Microsoft 365 Microsoft 365 Apps For Enterprise Microsoft Excel 2016 Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 For Mac Microsoft Office Ltsc 2021 Microsoft Office Ltsc 2024 Microsoft Office Ltsc For Mac 2021 Microsoft Office Ltsc For Mac 2024 Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Office Online Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-30T15:24:56.154Z

Reserved: 2026-08-27T20:58:07.630Z

Link: CVE-2026-81956

cve-icon Vulnrichment

Updated: 2026-09-09T09:52:35.152Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:59.360

Modified: 2026-09-17T20:18:42.090

Link: CVE-2026-81956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:26Z

Weaknesses