CVE-2026-81959
Microsoft Excel Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowThis is a Microsoft Excel (and related Microsoft Office) security bug that can let an attacker run code on your computer if they can get you to open a specially prepared Excel file; small businesses should act because it targets a widely used product and the fixed versions are available.
CVE-2026-81959 is a Microsoft Office Excel issue (CWE-122/CWE-190) consistent with a memory corruption bug that can lead to local remote code execution when an attacker delivers a crafted Excel file that a user opens.
What to do now
- Check your installed Microsoft Office/Excel version and build number (including Microsoft 365 Apps, Office 2016/2019/2021/2024, and Office/Excel for Mac).
- Compare your build to the fixed builds: Microsoft 365 Apps → 16.0.20326.20140; Microsoft Excel/Office → 16.0.5569.1003 (or 16.0.10417.20207 / 16.0.14334.20906 / 16.0.17932.20976 depending on your Office branch).
- Upgrade/apply Microsoft updates immediately until your build reaches one of the fixed versions listed for your product.
- After updating, review recent email attachments and downloaded Excel files from outside the business and remove/quarantine any that users opened.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-81959 and every CVE in our database. Create a free account — no credit card required.
Create Free Account