Exposure of Sensitive System Information to an Unauthorized Control Sphere in Microsoft products - CVE-2026-81387
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel when used locally. A remote attacker can exploit the vulnerability locally to disclose sensitive information.
User interaction is required. Disclosure is limited to memory-related information, specifically a heap address returned by the affected service. The Preview Pane is not an attack vector.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office
How to mitigate CVE-2026-81387
Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft Office - addressed in versions 16.0.5569.1003, 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976