PatchSiren cyber security CVE debrief
CVE-2026-81390 Microsoft CVE debrief
Microsoft Office Excel is vulnerable to an out-of-bounds read, allowing unauthorized attackers to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. This issue affects Microsoft Office Excel installations, which defenders should assess for exposure and prioritize patching vulnerable systems to prevent potential information disclosure. The CVE record and NVD vulnerability detail page provide additional information on the vulnerability.
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-17
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-17
Who should care
Defenders responsible for Microsoft Office Excel installations should assess exposure and prioritize patching vulnerable systems to prevent potential information disclosure. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review and apply vendor-provided updates.
Why it matters
Defenders should prioritize patching vulnerable Microsoft Office Excel installations to prevent potential information disclosure. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity.
- Potential information disclosure
- Need to verify and apply vendor-provided updates
- Monitoring for potential information disclosure attempts
Technical summary
The vulnerability is caused by an out-of-bounds read in Microsoft Office Excel, which allows unauthorized attackers to disclose information locally. This issue has a CVSS score of 5.5 and is classified as MEDIUM severity. Defenders should prioritize patching vulnerable Microsoft Office Excel installations to prevent potential information disclosure. The CVE record and NVD vulnerability detail page provide additional technical context.
Defensive priority
Defenders should prioritize patching vulnerable Microsoft Office Excel installations to prevent potential information disclosure.
Recommended defensive actions
- Patch vulnerable Microsoft Office Excel installations
- Verify and apply vendor-provided updates
- Monitor for potential information disclosure attempts
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its CVSS score and severity. Evidence is based on official CVE Program and NIST NVD sources. Defenders should verify affected scope and apply vendor-provided updates. The vulnerability allows unauthorized attackers to disclose information locally, with a CVSS score of 5.5 and MEDIUM severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81390 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81390
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81390 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81390
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81390
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.