cbcvebase.
CVE-2026-81387
published 2026-09-08

CVE-2026-81387: Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information…

PriorityP427medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.41%
34.5th percentile
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < 16.0.20326.2013816.0.20326.20138
microsoftmicrosoft_excel_2016>= 16.0.0.0 < 16.0.5569.100316.0.5569.1003
microsoftmicrosoft_office_2016>= 16.0.0 < 16.0.5569.100316.0.5569.1003
microsoftmicrosoft_office_2019>= 19.0.0 < 16.0.10417.2020716.0.10417.20207
microsoftmicrosoft_office_365_for_mac
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < 16.0.14334.2090616.0.14334.20906
microsoftmicrosoft_office_ltsc_2024>= 16.0.0 < 16.0.17932.2097616.0.17932.20976
microsoftmicrosoft_office_ltsc_for_mac_2021
microsoftmicrosoft_office_ltsc_for_mac_2024
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.